<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CyberSec &amp; FinTech en - Kancelaria LBKP</title>
	<atom:link href="https://lbkp.pl/en/category/cybersec-fintech-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://lbkp.pl</link>
	<description>Doradztwo prawne NewTech, RODO, cyberbezpieczeństwo, e-commerce, IP, M&#38;A, nieruchomości. PL, EN, DE, IT, ES, UA, RU.</description>
	<lastBuildDate>Mon, 27 Jul 2026 13:16:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://lbkp.pl/wp-content/uploads/2024/02/sygnet-rgb-2-e1755872238786-100x100.png</url>
	<title>CyberSec &amp; FinTech en - Kancelaria LBKP</title>
	<link>https://lbkp.pl</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AML is &#8220;sailing&#8221; into broader waters. Do you know who is responsible for it today?</title>
		<link>https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 13:16:05 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48564</guid>

					<description><![CDATA[<p>Table of Contents For years, anti-money laundering (AML) was primarily associated with banks, financial institutions, beneficial owner forms, and a million questions about where the client got their&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/">AML is “sailing” into broader waters. Do you know who is responsible for it today?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Table of Contents</p>



<ol class="wp-block-list">
<li><a href="#the-bank-is-no-longer-the-sole-gatekeeper">The bank is no longer the sole gatekeeper</a></li>



<li><a href="#a-procedure-is-no-longer-a-shelf-ware-alibi">A procedure is no longer a &#8220;shelf-ware alibi&#8221;</a></li>



<li><a href="#should-you-have-known">&#8220;Should you have known?&#8221;</a></li>



<li><a href="#a-companys-problem-can-quickly-become-a-board-members-problem">A company&#8217;s problem can quickly become a board member&#8217;s problem</a></li>



<li><a href="#aml-is-becoming-an-element-of-enterprise-management">AML is becoming an element of enterprise management</a></li>



<li><a href="#the-new-boundary-of-liability">The new boundary of liability</a></li>



<li><a href="#aml-is-entering-new-sectors-today">AML is entering new sectors today. But above all, it is entering boardrooms.</a></li>
</ol>



<p class="wp-block-paragraph">For years, anti-money laundering (AML) was primarily associated with banks, financial institutions, beneficial owner forms, and a million questions about where the client got their money from. It was a world of procedures, transaction alerts, and specialists locked away in compliance departments. That world is now definitively coming to an end.</p>



<p class="wp-block-paragraph">AML is increasingly ceasing to be the exclusive domain of the financial sector. Meanwhile, its core requirements are making their way into law firms, tech companies, accounting offices, estate agencies, crypto market operators, luxury goods traders, and even professional sports. The EU AML package further expands the catalogue of obliged entities to include, among others, a significant portion of the crypto sector, luxury goods dealers, as well as professional football clubs and agents.</p>



<p class="wp-block-paragraph">At the same time, the European Anti-Money Laundering Authority (AMLA) has been established to strengthen and harmonise supervision across the entire system. However, this is not just about adding more industries to the legislation. Much more important is the shift in how liability is perceived.</p>



<h2 class="wp-block-heading">The bank is no longer the sole gatekeeper</h2>



<p class="wp-block-paragraph">The AML system is based on the premise that it is not only the state that is supposed to &#8220;hunt down&#8221; criminals. Private entities standing between the client and the transaction are also expected to assist.</p>



<p class="wp-block-paragraph">A bank sees the flow of money. An accountant knows the settlement structure. An estate agent sees who is buying the apartment. An advisor helps structure a transaction. A law firm may be involved in setting up a company, acquiring a business, or managing a client&#8217;s assets. In the eyes of the European legislator, each of these entities is a gatekeeper to the legitimate economy.</p>



<p class="wp-block-paragraph">In Poland, advocates, attorneys-at-law, foreign lawyers, and tax advisors are already obliged entities when they provide assistance concerning, inter alia, the buying and selling of real estate or enterprises, managing assets, opening accounts, making contributions, and creating or managing companies. This does not mean that every piece of legal advice is subject to AML. It does mean, however, that a law firm participating in certain transactions can no longer assume that the issue of the origin of funds is solely the bank&#8217;s problem.</p>



<p class="wp-block-paragraph">The same applies to entrepreneurs. Not every entrepreneur is directly an obliged entity. However, almost anyone can encounter AML as a bank client, a participant in a transaction, an entity disclosing its ultimate beneficial owner, or a contractor whose ownership structure, funding source, or payment routing starts to raise questions.</p>



<p class="wp-block-paragraph">AML is therefore spilling beyond the formal statutory catalogue. It enters ordinary business operations through the back door, via banks, contractors, audits, financing, and corporate group requirements. The only limitation here is the &#8220;processing capacity&#8221; of the supervisory authorities.</p>



<h2 class="wp-block-heading">A procedure is no longer a &#8220;shelf-ware alibi&#8221;</h2>



<p class="wp-block-paragraph">Even a few years ago, many organisations treated compliance quite simply: we write a voluminous procedure that is essentially unreadable, conduct some generic training, collect signatures, and place the document in a suitably thick binder or a beautifully named folder on a shared drive.</p>



<p class="wp-block-paragraph">The binder had one fundamental advantage: it looked professional, and the drive was backed up.</p>



<p class="wp-block-paragraph">The problem is that regulators are increasingly less likely to ask merely whether a procedure existed. They ask whether it was tailored to the actual business model, whether it identified specific risks, whether it was updated, and whether anyone checked if it was working.</p>



<p class="wp-block-paragraph">In the current approach, risk assessment cannot be reduced to labelling a client as &#8220;low&#8221;, &#8220;normal&#8221;, or &#8220;high&#8221;. The risk category must influence the scope and intensity of the actions actually taken. A change in product, distribution channel, geographical area, client structure, or political situation may require an immediate update of the assessment. The authority also expects the documentation to allow for the verification of the effectiveness of the measures applied, and for the risk assessment to be approved by responsible persons at the management level.</p>



<p class="wp-block-paragraph">In other words, a procedure sitting on a server proves at most that someone knew how to write or outsource writing. It does not prove that the organisation knows how to manage risk.</p>



<h2 class="wp-block-heading">&#8220;Should you have known?&#8221;</h2>



<p class="wp-block-paragraph">This is where the most dangerous shift occurs.</p>



<p class="wp-block-paragraph">Liability is increasingly not based solely on the question of whether someone actually knew about the suspicious nature of a transaction. The question of whether you <em>should have</em> noticed it under a properly organised system is becoming ever more crucial.</p>



<p class="wp-block-paragraph">Did the client&#8217;s profile match the nature of the transaction? Was the source of funds credible? Did the ownership structure make commercial sense? Was the sudden change in payment routing explained? Did the intermediary have a genuine business justification? Did anyone connect several seemingly neutral pieces of information?</p>



<p class="wp-block-paragraph">This is no longer a classic document check. It is an obligation to draw conclusions.</p>



<p class="wp-block-paragraph">The regulator does not expect clairvoyance. However, they do expect the organisation to know its own business well enough to spot anomalies. And when something is missed, a very uncomfortable question will arise: was it a failure of the employee, the procedure, the IT system, or perhaps the management board that approved an operational model without adequate safeguards? This is precisely where the boundary between compliance and personal liability blurs.</p>



<h2 class="wp-block-heading">A company&#8217;s problem can quickly become a board member&#8217;s problem</h2>



<p class="wp-block-paragraph">The Polish AML Act does not leave this solely in the realm of best practices.</p>



<p class="wp-block-paragraph">In an obliged entity where a management board operates, a person responsible for the implementation of AML duties must be designated from among its members. This is not an honorary function or a mere footnote in an organisational resolution. The Act allows for financial penalties to be imposed on persons responsible for fulfilling AML obligations. It also provides for the possibility of a temporary ban on holding managerial positions. In specific cases, breaches of reporting obligations may even lead to criminal liability.</p>



<p class="wp-block-paragraph">Naturally, a board member is not expected to personally analyse every transaction. However, they are expected to ensure that there is an efficient system, adequate resources, a clear division of responsibilities, and a realistic escalation path.</p>



<p class="wp-block-paragraph">Therefore, it is not enough to say, &#8220;We have an AML officer for that&#8221;.</p>



<p class="wp-block-paragraph">The board may delegate the execution of tasks. It cannot delegate the entire problem and then pretend that AML reports were just an exotic, graphically pleasing addition to the board meeting materials.</p>



<p class="wp-block-paragraph">Situations where the compliance unit has been signalling staff shortages, inefficient tools, backlogs in client reviews, or data quality issues for months, while the management merely notes the information and calmly moves on to the sales agenda, become particularly risky.</p>



<p class="wp-block-paragraph">Such a meeting minute may one day turn out to be more interesting than many a procedure.</p>



<h2 class="wp-block-heading">AML is becoming an element of enterprise management</h2>



<p class="wp-block-paragraph">The biggest mistake today is treating AML as an isolated regulatory island. Money laundering risk is intertwined with sanctions risk, corruption, tax, reputational, cyber risks, and the criminal liability of management.</p>



<p class="wp-block-paragraph">A new product, expansion into a foreign market, a company acquisition, a venture into digital assets, serving clients from high-risk countries, or a change in the payment model are not purely business decisions. They should also trigger questions about AML implications.</p>



<p class="wp-block-paragraph">Therefore, a properly functioning system cannot be built once and for all. It must respond to changes in the company&#8217;s operations. If the business has changed but the risk assessment remains the same, it usually does not mean the risk has been stable. It means nobody has looked at the document.</p>



<h2 class="wp-block-heading">The new boundary of liability</h2>



<p class="wp-block-paragraph">AML is no longer just about fighting a suitcase of cash brought into a bank by a man in dark glasses looking like someone from a B-movie gangster film. Today&#8217;s risk hides in multi-level ownership structures, cross-border payments, digital assets, seemingly legitimate investments, brokerage agreements, and transactions, each of which looks perfectly innocent on its own.</p>



<p class="wp-block-paragraph">Consequently, the expectations towards those responsible for the organisation are also changing. It is not enough not to know. You also have to demonstrate that the organisation did everything that could reasonably be expected of it to find out. And this is exactly where the comfortable world of compliance understood as a set of documents ends. What begins is accountability for decisions, omissions, lack of resources, and risks that nobody wanted to see.</p>



<h2 class="wp-block-heading">AML is entering new sectors today. But above all, it is entering boardrooms.</h2>



<p class="wp-block-paragraph">AML is entering new sectors today. But above all, it is entering boardrooms, and it is there that the decision is made as to whether the company truly understands its risks or merely possesses a document covering them. If you are not sure which side your organisation stands on, we will help you find out before the regulator asks.</p>



<p class="wp-block-paragraph"></p><p>The post <a href="https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/">AML is “sailing” into broader waters. Do you know who is responsible for it today?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity in local government – from a technical issue to a board agenda item</title>
		<link>https://lbkp.pl/en/47499-2/</link>
		
		<dc:creator><![CDATA[Paulina Jeziorska]]></dc:creator>
		<pubDate>Thu, 07 May 2026 09:02:29 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=47499</guid>

					<description><![CDATA[<p>The amended Act on the National Cybersecurity System, implementing the NIS2 Directive, has been in force since 3 April. The debate on the new obligations has focused mainly&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/47499-2/">Cybersecurity in local government – from a technical issue to a board agenda item</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The amended Act on the National Cybersecurity System, implementing the NIS2 Directive, has been in force since 3 April. The debate on the new obligations has focused mainly on the private sector – and wrongly so. The regulation also covers public entities, including local government bodies, their organisational units and municipal companies.</p>



<p class="wp-block-paragraph">Our experts Paulina Jeziorska and Zuzanna Prandecka-Walek have analysed this topic in Dziennik Gazeta Prawna. In the article, they discuss step by step what the amendment means in practice for local authorities – from determining who is subject to the new regulations, through the catalogue of obligations, to the sanctions regime.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="439" src="https://lbkp.pl/wp-content/uploads/2026/05/2673-1024x439.jpg" alt="" class="wp-image-47496" srcset="https://lbkp.pl/wp-content/uploads/2026/05/2673-1024x439.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/05/2673-300x129.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/05/2673-768x329.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/05/2673-1536x658.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/05/2673-370x159.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/05/2673-840x360.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/05/2673-410x176.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/05/2673.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">A few points worth noting:</h2>



<p class="wp-block-paragraph">A new classification of entities. The previous model, which distinguished between operators of key services and digital service providers, is being replaced by a classification into key entities and important entities. In the case of local authorities, the decisive factor is not the scale of their operations, but the type of authority and its position within the structure. Key entities include, amongst others, district authorities and local councils employing at least 50 people. Important entities, in turn, include local government budgetary units, budgetary institutions, cultural institutions and municipal companies – provided they carry out public tasks using information systems.</p>



<p class="wp-block-paragraph">The obligations go far beyond mere formalities. Implementing an information security management system, handling and reporting incidents, ensuring business continuity, and streamlining relations with suppliers – this is not a one-off project, but a permanent change in the way the organisation operates. For important entities that are public bodies, the legislator has also provided a specific list of minimum requirements in an annex to the Act.</p>



<p class="wp-block-paragraph">The penalties are substantial. Fines can reach up to €10 million for critical entities and €7 million for important entities. The head of the entity is held personally liable – up to 100% of their salary in the case of public entities. The regulations grant the authority some flexibility in determining the penalty, taking into account, among other things, the entity’s financial capacity, but the lower thresholds are set by law.</p>



<p class="wp-block-paragraph">A key point of interpretation: is a key entity that does not use information systems to carry out public tasks completely exempt from these obligations? The wording of the regulations does not provide a clear answer, which in practice may create uncertainty for local authorities.</p>



<p class="wp-block-paragraph">For many local authorities, the coming months will test their ability to rapidly build up the expertise and structures that they simply have not needed until now. Putting this off is no longer an option.</p>



<h2 class="wp-block-heading">The full article by Paulina Jeziorska and Zuzanna Prandecka-Walek is available in Dziennik Gazeta Prawna:</h2>



<div class="wp-block-essential-blocks-button  root-eb-button-4tojd"><div class="eb-parent-wrapper eb-parent-eb-button-4tojd "><div class="eb-button-wrapper eb-button-alignment eb-button-4tojd"><div class="eb-button"><div class="eb-button-inner-wrapper "><a class="eb-button-anchor  " href="https://edgp.gazetaprawna.pl/samorzad/cyfryzacja-i-e-uslugi-publiczne/artykuly/11226093,cyberbezpieczenstwo-nowe-obowiazki-uderza-rowniez-w-podmioty-publiczn.html" rel="noopener">Link to the full article</a></div></div></div></div></div><p>The post <a href="https://lbkp.pl/en/47499-2/">Cybersecurity in local government – from a technical issue to a board agenda item</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MiCA does not cover DeFi. What does this mean for the crypto asset market in the EU?</title>
		<link>https://lbkp.pl/en/6556-2/</link>
		
		<dc:creator><![CDATA[Paulina Jeziorska]]></dc:creator>
		<pubDate>Thu, 24 Jul 2025 07:27:26 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6556</guid>

					<description><![CDATA[<p>On 31 May 2024, Regulation (EU) 2023/1114 (‘MiCA’) entered into force, opening a new chapter in the regulation of the crypto-asset market in the EU. Many observers welcomed&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/6556-2/">MiCA does not cover DeFi. What does this mean for the crypto asset market in the EU?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>On 31 May 2024, Regulation (EU) 2023/1114 (‘MiCA’) entered into force, opening a new chapter in the regulation of the crypto-asset market in the EU. Many observers welcomed this act with enthusiasm, considering it a ‘complete’ code for the industry. However, this enthusiasm proved premature. Even a cursory analysis reveals a significant gap: MiCA does not cover the phenomenon of decentralised finance (DeFi), including decentralised cryptocurrency exchanges (DEXs), where services are provided not by an identifiable operator but by code stored on a blockchain network. In doing so, the EU legislator has left out of the scope of regulation a segment which, from the perspective of technological innovation, best illustrates the revolution brought about by DLT technology.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/2-1.jpg"><img decoding="async" class="aligncenter size-full wp-image-6550" src="https://lbkp.pl/wp-content/uploads/2025/07/2-1.jpg" alt="MiCA Polska krypto" width="1440" height="450" /></a></span></p>
<h2><b>The illusion of full regulation</b></h2>
<p>MiCA, in Article 2 and the recitals of the preamble, provides for significant exclusions. MiCA does not apply to, among other things:</p>
<ul>
<li>deposits, including structured deposits,</li>
<li>cash (unless they meet the definition of e-money tokens),</li>
<li>NFT tokens, provided they are ‘unique and non-fungible’;</li>
</ul>
<p>However, it will be crucial to pay attention to recital 22 of MiCA. In this recital, the legislator stated that ‘where crypto-asset services are provided in a <b><i>fully decentralised manner, without intermediaries</i></b><i>, they should not be covered by this Regulation.’</i></p>
<p>Therefore, MiCA effectively covers only centralised or hybrid models. Services where there is no operator, provider or controller are not covered by the new rules.</p>
<h2><b>Lack of DeFi regulation: the premise of ‘fully decentralised’</b></h2>
<p>In practice, not all DeFi business models will meet the criterion of full decentralisation.</p>
<p>Recital 22 of MiCA indicates that the regulation does not cover services provided in a ‘fully decentralised manner, without intermediaries’. Although the term ‘intermediary’ is not defined, it can be assumed that it refers to a legal entity that is actively involved in the operation, provision or control of services related to crypto-assets, whether directly or indirectly.</p>
<p>As a result, the assessment of ‘full decentralisation’ may require determining in each case whether any entity influences the functioning of the protocol or interface. Unfortunately, the EU legislator has not provided more detailed criteria or proposed a definition that would make it easier for supervisory authorities and market participants to clearly classify entities, which is likely to cause interpretation complications in the near future.</p>
<p>In practice, therefore, it will be the national supervisory authority – in Poland, the Financial Supervision Authority – that will decide whether a particular DeFi is subject to MiCa and whether it requires a CASP authorisation. For the time being, there are no detailed guidelines to assist in making such a decision, but it is likely that EU authorities will provide guidance on what elements should be taken into account in order to assess whether certain services are provided in a fully decentralised manner without intermediaries or not.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/3-1.jpg"><img decoding="async" class="aligncenter size-full wp-image-6551" src="https://lbkp.pl/wp-content/uploads/2025/07/3-1.jpg" alt="MiCA Polska krypto" width="1440" height="450" /></a></span></p>
<h2><b>Partial decentralisation remains subject to MiCA</b></h2>
<p>The ‘comfort’ of no regulation is not provided by <b>partial</b> decentralisation. Recital 22 itself stipulates that if <i>‘part of such activities or services are carried out in a decentralised manner’</i>, MiCA obligations remain in force. Such a modern hybrid could be a <b>DEX with an upgrade key,</b> i.e. a smart contract that can be changed or suspended by the project management. In practice, such a protocol is not fully decentralised, as there is an entity that retains the ability to interfere with its functioning.</p>
<p>In such configurations, it may be possible to identify the controlling entity (even partially), and therefore the competent national authority may consider that such an entity can only operate after obtaining a CASP licence.</p>
<h2><b>Issuance of crypto-assets ‘without an issuer’</b></h2>
<p>The second exception provided for in recital 22 does not concern services but the <b>issuance of crypto-assets</b>. If a crypto asset <i>‘has no identifiable issuer’</i>, the provisions of Titles II to IV of MiCA (concerning, inter alia, the information document, obligations towards token holders, issuance, offering and admission to trading of crypto assets) <b>do not apply</b>.</p>
<p>This exception may apply to issues made <b>directly by an on-chain protocol launched without a central entity</b>, e.g. through a fair launch or automatic minting mechanism, without the involvement of any managing person.</p>
<p>It is worth noting that MiCA does not specify what specific characteristics should determine whether a particular entity can be considered an issuer. Nevertheless, the degree of control over the issuance process and the possibility of linking specific persons or structures to the management of the issuance or the economic benefits derived from it may be of key importance.</p>
<h2><b>Practical consequences for the market</b></h2>
<ul>
<li><b>The national authority</b> (in Poland – the Polish Financial Supervision Authority) will have to determine whether there is an ‘intermediary’ in a given project model and whether the issuer can be identified. Under the draft Polish law on the cryptoasset market (June 2025), the KNF will gain instruments to restrict access to or block the interface to such a website.</li>
<li><b>Entrepreneurs</b> should assess the level of centralisation of their products today. Projects that use multisig to upgrade a contract, charge transaction fees or control issuance revenues, or set rules for service/token management may qualify as CASPs.</li>
<li><b>Investors</b> should be aware that the absence of an issuer or CASP also means that there is no European regulatory protection under MiCA.</li>
</ul>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/4-1.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6552" src="https://lbkp.pl/wp-content/uploads/2025/07/4-1.jpg" alt="MiCA Polska krypto" width="1440" height="450" /></a></span></p>
<h2><b>Conclusions</b></h2>
<p>MiCA is only the first step towards a harmonised crypto-asset market. By drawing a line in recital 22, the European legislator has recognised that DeFi requires a separate – perhaps entirely new – regulatory approach. Until such a framework is developed:</p>
<ul>
<li><b>full decentralisation</b> remains the only way for a service to fall completely outside MiCA;</li>
<li><b>any element of centralisation</b> may entail licensing obligations;</li>
<li><b>the national authority</b> will have to assess whether it is dealing with DeFi or not.</li>
</ul><p>The post <a href="https://lbkp.pl/en/6556-2/">MiCA does not cover DeFi. What does this mean for the crypto asset market in the EU?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>MiCA in Poland – a compendium of knowledge about transition periods and deadlines in the draft law on the crypto-asset market</title>
		<link>https://lbkp.pl/en/mica-in-poland-a-compendium-of-knowledge-about-transition-periods-and-deadlines-in-the-draft-law-on-the-crypto-asset-market/</link>
		
		<dc:creator><![CDATA[Paulina Jeziorska]]></dc:creator>
		<pubDate>Mon, 21 Jul 2025 08:03:55 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6457</guid>

					<description><![CDATA[<p>Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (MiCA) is a landmark piece of legislation adopted by the European Union aimed&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/mica-in-poland-a-compendium-of-knowledge-about-transition-periods-and-deadlines-in-the-draft-law-on-the-crypto-asset-market/">MiCA in Poland – a compendium of knowledge about transition periods and deadlines in the draft law on the crypto-asset market</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (MiCA) is a landmark piece of legislation adopted by the European Union aimed at harmonising rules on crypto-assets across the EU. The introduction of MiCA is a response to the growing popularity of digital assets. The implementation of the new regulations brings significant changes for Polish companies and all participants in the cryptocurrency market. In this article, we comprehensively explain the most important issues concerning the MiCA transition period, as well as the details of Polish legislative solutions that will affect the activities of crypto-asset service providers (CASPs).</span></p>
<p><span style="color: #000000;">You can read more about this here: <a style="color: #000000;" href="https://lbkp.pl/rozpoczecie-stosowania-mica-co-oznacza-dla-rynku-krypto-w-polsce/">https://lbkp.pl/rozpoczecie-stosowania-mica-co-oznacza-dla-rynku-krypto-w-polsce/</a></span></p>
<h2><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/157.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6449" src="https://lbkp.pl/wp-content/uploads/2025/07/157.jpg" alt="MiCA Polska krypto" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/07/157.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/07/157-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/07/157-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/07/157-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/07/157-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/07/157-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/07/157-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/07/157-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></h2>
<h2><span style="color: #000000;">MiCA transition period at EU level – 18-month safety buffer</span></h2>
<p><span style="color: #000000;">The basic premise of the MiCA Regulation is to introduce a certain ‘time buffer’ during which existing crypto-asset service providers will be able to operate under the old rules laid down in national legislation. According to Article 143(3) of the MiCA Regulation, this period is <b>18 months</b> from the date of application of the new rules, until <b>1 July 2026</b>.</span></p>
<p><span style="color: #000000;">During this time, companies providing crypto-asset services may continue to operate in accordance with existing local regulations until they obtain the formal authorisation required by MiCA in accordance with Article 63 or until such authorisation is refused, whichever comes first. This is a particularly important stage for all entities, both those already present on the market and new players planning to enter the cryptocurrency market in the European Union.</span></p>
<h2><span style="color: #000000;">Flexibility in setting transition periods at national level</span></h2>
<p><span style="color: #000000;">MiCA provides flexibility for Member States in determining the length of the transition period. Recital 114 of the Regulation emphasises that if national regulations in force before 30 December 2024 were significantly less stringent than the MiCA requirements, Member States may decide to shorten or even omit the transitional period. This allows them to raise the standards of crypto-asset entities more quickly to the level set by the EU.</span></p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/160.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6452" src="https://lbkp.pl/wp-content/uploads/2025/07/160.jpg" alt="MiCA Polska krypto" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/07/160.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/07/160-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/07/160-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/07/160-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/07/160-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/07/160-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/07/160-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/07/160-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><span style="color: #000000;">Article 143(3) MiCA – specific conditions for the use of the transitional period in the EU</span></h2>
<p><span style="color: #000000;">Pursuant to Article 143(3) of MiCA, crypto-asset service providers who provided their services in accordance with applicable national law before 30 December 2024 may continue to operate under the existing rules until 1 July 2026, until they obtain authorisation under Article 63 of MiCA or until authorisation is refused. Only these companies will be eligible for transitional arrangements – companies that commence operations after that date will be subject to the full MiCA regime from the outset.</span></p>
<h2><span style="color: #000000;">Provisions concerning entities not covered by the register of virtual currency activities in Poland</span></h2>
<p><span style="color: #000000;">Poland is participating in the process of implementing the MiCA Regulation and in June 2025 submitted a draft law on the crypto-asset market to the Sejm.</span></p>
<p><span style="color: #000000;">Pursuant to Article 162 of the draft law, an entity which, on 29 December 2024, provided crypto-asset services within the meaning of Article 3(1)(16) of MiCA (for more information on the scope of services, see <a style="color: #000000;" href="https://lbkp.pl/rozpoczecie-stosowania-mica-co-oznacza-dla-rynku-krypto-w-polsce/">https://lbkp.pl/rozpoczecie-stosowania-mica-co-oznacza-dla-rynku-krypto-w-polsce/</a>), but which do not constitute economic activities consisting in the provision of services in the field of:</span></p>
<p><span style="color: #000000;">a) exchange between virtual currencies and means of payment,</span></p>
<p><span style="color: #000000;">b) exchange between virtual currencies,</span></p>
<p><span style="color: #000000;">c) intermediation in the exchange referred to in point (a) or (b),</span></p>
<p><span style="color: #000000;">d) keeping accounts referred to in Article 2(17)(E) of the AML Act</span></p>
<p><span style="color: #000000;">&#8211; may provide these services in relation to crypto assets under the existing rules, but for no longer than:</span></p>
<ul>
<li><span style="color: #000000;"><b>4 months from the entry into force of the draft Act</b>,</span></li>
<li><span style="color: #000000;"><b>or for 9 months from the date of entry into force of the draft act, if, within 3 months of the date of entry into force of this act, it submits a complete application for the issuance of this authorisation and receives the notification</b> referred to in Article 63(4) of the MiCA Regulation.</span></li>
</ul>
<h2><span style="color: #000000;">Regulations for companies entered in the VASP register (i.e. the register of virtual currency activities) in Poland</span></h2>
<p><span style="color: #000000;">For companies that were entered in the national <b>VASP</b> register on the date of entry into force of the draft act, similar rules apply – <b>they may continue to operate under the existing rules for 4 months from the date of entry into force of the draft law, or for 9 months from the date of entry into force of the draft law if they submit a complete application within the prescribed time limit and receive notification of acceptance of the application.</b></span></p>
<p><span style="color: #000000;">An exception is if such an entity is removed from the register before the expiry of the specified time limits.</span></p>
<h2><span style="color: #000000;">Practical consequences for the market – what do companies need to do?</span></h2>
<p><span style="color: #000000;">The regulatory changes resulting from MiCA and the Polish Cryptoasset Market Act impose an obligation on companies to closely monitor the current legal situation and develop an implementation strategy. The key actions that companies operating on the market should take include, in particular:</span></p>
<ul>
<li><span style="color: #000000;">verifying their current legal status (whether the company is registered as a VASP, whether it has been operating in accordance with the existing regulations),</span></li>
<li><span style="color: #000000;">preparing a complete set of documentation necessary to apply for a CASP licence,</span></li>
<li><span style="color: #000000;">monitoring transition deadlines and responding quickly to any changes in legislation,</span></li>
<li><span style="color: #000000;">implementing new internal procedures in accordance with MiCA and national requirements and guidelines from supervisory authorities.</span></li>
<li><span style="color: #000000;">Failure to meet deadlines or lack of adequate preparation may result in the loss of the ability to operate on the crypto asset market in Poland and throughout the EU.</span></li>
</ul>
<h2><span style="color: #000000;">Documentation and formal obligations – challenges for companies</span></h2>
<p><span style="color: #000000;">Preparing for the full implementation of MiCA will require companies to conduct an in-depth analysis and carry out numerous formal and legal activities. The CASP registration process is multi-stage and includes:</span></p>
<ul>
<li><span style="color: #000000;">developing AML/KYC policies and measures to prevent money laundering and terrorist financing,</span></li>
<li><span style="color: #000000;">preparing compliance documentation and risk management rules,</span></li>
<li><span style="color: #000000;">implementing comprehensive IT security and personal data protection procedures,</span></li>
<li><span style="color: #000000;">providing detailed descriptions of services, products, technological architecture and mechanisms for securing customer funds,</span></li>
<li><span style="color: #000000;">presenting risk analyses and business continuity plans.</span></li>
<li><span style="color: #000000;">You can read more about this here: <a style="color: #000000;" href="https://lbkp.pl/uzyskanie-zezwolenia-casp-kluczowe-informacje-dla-firm-kryptowalutowych/">https://lbkp.pl/uzyskanie-zezwolenia-casp-kluczowe-informacje-dla-firm-kryptowalutowych/</a></span></li>
</ul>
<h2 aria-level="2"><span style="color: #000000;"><a style="font-size: 16px; color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/07/158.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6450" src="https://lbkp.pl/wp-content/uploads/2025/07/158.jpg" alt="MiCA Polska krypto" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/07/158.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/07/158-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/07/158-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/07/158-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/07/158-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/07/158-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/07/158-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/07/158-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></h2>
<h2><span style="color: #000000;">Why start preparing for MiCA now?</span></h2>
<p><span style="color: #000000;">Currently, despite the fact that the act implementing MiCA in Poland has not yet entered into force, it is worth starting to prepare documentation and analyse your own activities in terms of the new regulations in advance. Companies with a complete set of ready-made documents will be able to go through the CASP registration process faster and obtain the required permits. This allows for smooth continuation of operations and gaining a competitive advantage in the market.</span></p>
<p><span style="color: #000000;">Importantly, current legislative analyses do not indicate any risk of significant changes to the key provisions of the draft law, which is why preparatory measures are already fully justified at this stage.</span></p>
<h2><span style="color: #000000;">No possibility to submit an application before the law enters into force</span></h2>
<p><span style="color: #000000;">It is not yet possible to submit an application for CASP registration to the relevant authority, as the law enabling this process has not yet entered into force. However, our clients are providing services in accordance with the existing regulations, while preparing with us the documentation necessary to apply for a CASP licence.</span></p>
<p><span style="color: #000000;">The work on the bill so far does not indicate that the draft will undergo major changes. We recommend that you start preparing all the required documents now. Due to the broad scope of the guidelines already set by the EU authorities, completing all the documentation and introducing the necessary procedures may be time-consuming and require careful planning. Starting these preparations in advance will allow you to go through the registration process smoothly and adapt your business to the new requirements.</span></p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/92.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5924" src="https://lbkp.pl/wp-content/uploads/2025/03/92.jpg" alt="krypto" width="1440" height="450" /></a></span></p>
<h2><span style="color: #000000;">Gain an edge with professional MiCA support</span></h2>
<p><span style="color: #000000;">The implementation of the MiCA Regulation and the new Crypto Asset Market Act in Poland requires a multi-stage, well-planned process covering legal, technical and management issues. Proper preparation and understanding of the transition periods are key to the smooth functioning of the crypto asset services market, both for existing and new entities.</span></p>
<p><span style="color: #000000;">Our law firm offers comprehensive support in the implementation of MiCA requirements – from completing documentation and training staff to ongoing compliance support and legal advice. We encourage companies that want to efficiently and effectively adapt to the new regulations to contact us – from consultation, through the preparation of policies and procedures, to the finalisation of the CASP registration process.</span></p>
<p><span style="color: #000000;">Don&#8217;t wait until the last minute – a delayed response to legislative changes may mean losing your competitive position and growth opportunities. Contact us!</span></p><p>The post <a href="https://lbkp.pl/en/mica-in-poland-a-compendium-of-knowledge-about-transition-periods-and-deadlines-in-the-draft-law-on-the-crypto-asset-market/">MiCA in Poland – a compendium of knowledge about transition periods and deadlines in the draft law on the crypto-asset market</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Types of crypto assets regulated by MiCA</title>
		<link>https://lbkp.pl/en/types-of-crypto-assets-regulated-by-mica/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Fri, 18 Jul 2025 08:11:49 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6388</guid>

					<description><![CDATA[<p>The MiCA (Markets in Crypto-Assets) Regulation is the first European Union legal act that comprehensively regulates the rights and obligations of issuers and service providers related to crypto-assets.&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/types-of-crypto-assets-regulated-by-mica/">Types of crypto assets regulated by MiCA</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<div>
<p>The MiCA (Markets in Crypto-Assets) Regulation is the first European Union legal act that comprehensively regulates the rights and obligations of issuers and service providers related to crypto-assets. The aim of MiCA is to ensure a high level of investor protection, particularly for retail investors, to increase the transparency of the crypto-asset market and to harmonise the rules governing this market across the European Union. Thanks to MiCA, the crypto-asset market is gaining clear rules, which promotes investment security and the development of the industry.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/04/128.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6221" src="https://lbkp.pl/wp-content/uploads/2025/04/128.jpg" alt="kryptowaluty kryptoaktywa" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/04/128.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/04/128-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/04/128-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/04/128-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/04/128-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/04/128-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/04/128-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/04/128-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
</div>
<div>
<h2><b>Types of crypto assets regulated by MiCA</b></h2>
<p><b>Types of crypto assets regulated by MiCA</b> include digital representations of value or rights stored electronically using distributed ledger technology (DLT) or similar technologies.</p>
<p><b>The MiCA Regulation</b> distinguishes between three main types of crypto assets, which differ in terms of their characteristics and level of risk. This distinction is crucial as it determines the regulatory obligations of companies issuing crypto assets or offering crypto assets to investors. Thanks to the clear definitions in MiCA, companies can align their activities with legal requirements and investors are better protected in the crypto asset market.</p>
<h2><b>Categories of crypto assets:</b></h2>
<h3><b>Asset-Referenced Tokens (ART)</b></h3>
<p>Asset-Referenced Tokens (ART) are cryptoassets whose purpose is to maintain a stable value by being linked to another value, right or combination thereof, including at least one fiat currency.</p>
<p>ARTs are not considered electronic money tokens (EMTs). The key difference is that the value of an ART cannot be determined solely by a single fiat currency. If a cryptoasset bases its value on more than one measure or on a combination of assets, including at least one official currency, it will be classified as an ART.</p>
<p>The issuer of an ART token is required to enable its redemption, either by paying cash other than electronic money corresponding to the market value of the assets associated with the token, or by delivering those assets.</p>
<ul>
<li>MiCA allows some flexibility in determining the ART value measure, but redemption must be possible in cash or through the delivery of the underlying asset.</li>
<li>In particular, the issuer should always ensure that redemption is possible in cash (other than electronic money) denominated in the same official currency that was accepted at the time of sale of the token.</li>
</ul>
<h3><b>E-Money Tokens (EMT)</b></h3>
<p><b>EMT tokens</b> are linked to a single official currency (e.g. the euro) and serve as a digital equivalent of traditional money. Their key feature is a <b>guaranteed redemption</b> at face value.</p>
<p>Only credit institutions or electronic money institutions may issue e-money tokens. These entities must ensure that token holders can exercise their redemption right at any time, at face value and in the currency to which the token is linked.</p>
<p>An example of such a token is stablecoins linked to the euro, which aim to maintain a 1:1 parity with the euro. Under MiCA, issuers of such tokens will have to meet strict regulatory requirements, including having the appropriate legal status and ensuring a real possibility of redemption of tokens at their nominal value.</p>
<h3><b>Other crypto assets</b></h3>
<p>This category includes <b>cryptocurrencies that are not classified as asset-backed tokens,</b> such as <b>Bitcoin</b> (BTC) and <b>Ethereum</b> (ETH), which do not have a value stabilisation mechanism. This group also includes <b>utility tokens</b>, which provide access to services or goods offered by the issuer.</p>
<p>This category also includes utility tokens, which give holders access to specific services or goods offered by the issuer. Such a token can be compared to a digital voucher or ticket entitling the holder to use a specific service or purchase a specific good.</p>
</div>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/04/130.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6222" src="https://lbkp.pl/wp-content/uploads/2025/04/130.jpg" alt="kryptowaluty kryptoaktywa MICA" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/04/130.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/04/130-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/04/130-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/04/130-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/04/130-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/04/130-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/04/130-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/04/130-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<div>
<h2><b>Crypto assets excluded from MiCA regulation</b></h2>
<p>MiCA does not cover all digital assets. The Regulation excludes from its scope certain categories of digital assets that are either already regulated by other EU legal acts or do not meet the definition of crypto assets within the meaning of MiCA. In particular, the provisions exclude <b>financial instruments</b> and <b>financial products</b> that are subject to MiFID II.</p>
<p><b>In accordance with Article 2(4) of the Regulation, the following are also excluded from the scope of MiCA:</b></p>
<ul>
<li>deposits, including structured deposits,</li>
<li>cash (unless they meet the definition of e-money tokens),</li>
<li>insurance, pension products and schemes.</li>
</ul>
<h3><b><i>Non-fungible tokens (NFTs)</i></b></h3>
<p>The MiCA Regulation also does not regulate non-fungible tokens (NFTs), provided that they are truly unique and non-fungible. This applies, for example, to digital artworks or unique collectibles in computer games.</p>
<p>However, it is important to note a significant distinction: if crypto assets are issued as non-fungible tokens as part of a large series or collection, this may be considered an indicator of their actual fungibility, which would result in them being subject to MiCA regulations. Furthermore, fractional parts of a unique and non-fungible crypto asset are not considered unique and non-fungible, so they will also be subject to MiCA regulations.</p>
<h3><b><i>Crypto assets limited to internal networks</i></b></h3>
<p>The MiCA Regulation also does not cover crypto assets used in closed networks, such as loyalty points or vouchers accepted only by their issuer. This exception applies to digital assets that operate within a limited ecosystem and are not intended for wider trading on the market.</p>
</div>
<div>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/04/129.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6223" src="https://lbkp.pl/wp-content/uploads/2025/04/129.jpg" alt="kryptowaluty kryptoaktywa MICA" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/04/129.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/04/129-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/04/129-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/04/129-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/04/129-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/04/129-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/04/129-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/04/129-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Conclusions and Recommendations</b></h2>
<p>We encourage you to contact a lawyer for comprehensive legal support in determining the classification of crypto assets and ensuring compliance with regulations governing the crypto asset and financial instrument markets.</p>
</div><p>The post <a href="https://lbkp.pl/en/types-of-crypto-assets-regulated-by-mica/">Types of crypto assets regulated by MiCA</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Obtaining a CASP licence – key information for crypto companies</title>
		<link>https://lbkp.pl/en/obtaining-a-casp-licence-key-information-for-crypto-companies/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 10:13:03 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6173</guid>

					<description><![CDATA[<p>The CASP (Crypto-Asset Service Provider) licence is a mandatory licence under the MiCA (Markets in Crypto-Assets) regulation that companies providing services related to crypto-assets in the European Union&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/obtaining-a-casp-licence-key-information-for-crypto-companies/">Obtaining a CASP licence – key information for crypto companies</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>The CASP (Crypto-Asset Service Provider) licence is a mandatory licence under the MiCA (Markets in Crypto-Assets) regulation that companies providing services related to crypto-assets in the European Union must obtain. This includes cryptocurrency exchanges and cryptocurrency exchange offices.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/114.jpg"><img loading="lazy" decoding="async" class="aligncenter wp-image-6072 size-full" src="https://lbkp.pl/wp-content/uploads/2025/03/114.jpg" alt="CASP" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/114.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/114-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/114-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/114-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/114-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/114-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/114-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/114-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>How to obtain a CASP licence?</b></h2>
<p>In order to operate in the field of crypto assets in accordance with MiCA regulations, entrepreneurs must meet certain requirements and submit an application to the relevant supervisory authority in their country.</p>
<h2><b>Requirements for physical presence in the EU</b></h2>
<p>In accordance with Article 59(2) of MiCA, crypto asset service providers must:</p>
<ul>
<li>Have their head office in a member state where they actually carry out at least part of their cryptoasset service business.</li>
<li>Have their place of effective management in the EU.</li>
<li>Have at least one director who is resident in the EU.</li>
</ul>
<p>Therefore, purely virtual operations without a physical presence in the EU do not meet the regulatory requirements.<b>Where do I apply for a CASP authorisation?</b></p>
<p>Entities applying for a CASP authorisation shall submit an application to the competent supervisory authority of their home Member State.</p>
<p>The home member state for a crypto-asset service provider will be the member state in which the crypto-asset service provider has its registered office.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/117.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6073" src="https://lbkp.pl/wp-content/uploads/2025/03/117.jpg" alt="CASP UE" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/117.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/117-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/117-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/117-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/117-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/117-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/117-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/117-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Does the CASP authorisation allow for the provision of services throughout the EU?</b></h2>
<p>Yes, once they have obtained a CASP licence, companies can provide crypto-asset services throughout the European Union under the freedom of establishment or the freedom to provide services. Importantly, cross-border activity does not require a physical presence in the host Member State.</p>
<h2><b>Requirements for board members of entities applying for a CASP</b></h2>
<p>Board members must:</p>
<ul>
<li>They must be of good repute, have a clean criminal record and have appropriate knowledge and experience.</li>
<li>They must not have been convicted of offences relating to money laundering or terrorist financing or of other offences that could affect their good repute.</li>
<li>At least one board member must be resident in the Union.</li>
<li>They must also demonstrate that they are able to dedicate sufficient time to effectively fulfil their duties.</li>
<li>They must not be subject to any penalty under commercial law, insolvency law, financial services regulations, anti-money laundering and anti-terrorist financing regulations, anti-fraud regulations or professional liability regulations.</li>
</ul>
<p>The fulfilment of these conditions must be documented with appropriate evidence and attached to the authorisation application. The supervisory authority will verify whether these conditions are actually met.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/116.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6074" src="https://lbkp.pl/wp-content/uploads/2025/03/116.jpg" alt="CASP" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/116.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/116-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/116-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/116-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/116-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/116-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/116-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/116-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Documents required for the CASP authorisation application</b></h2>
<p>The exact list of documents and information that must be included in the CASP application depends on the type of services that the applicant intends to provide according to Art. 3, Paragraph 1, No. 16 of the MiCA. Therefore, the first step in preparing an application should always be to identify the services you plan to provide and verify the requirements that the MiCA has set for the authorisation of these specific services.</p>
<p>However, based on the requirements set out in the MiCA regulation and the accompanying technical standards, it is possible to define a basic catalogue of documents and information that will need to be completed by an entity preparing to apply for a CASP licence. These will include:</p>
<ul>
<li>Identification data of the applicant.</li>
<li>Articles of association or partnership agreement.</li>
<li>Programme of activities and type of services planned, as well as the place and manner in which they will be provided.</li>
<li>Proof of compliance with the prudential requirements set out in Article 67 of the MiCA (documents confirming the required funds or guarantees, insurance policies if applicable).</li>
<li>Description of management principles &#8211; organisational structure of the applicant and internal supervision system and decision-making procedures.</li>
<li>Proof of good repute and competence of the members of the management body &#8211; (Criminal records and CVs as well as information on experience).</li>
<li>Description of internal control and risk management procedures (Policies and procedures for identifying, assessing and managing risks, procedures for combating money laundering and terrorist financing, and a business continuity plan).</li>
<li>Technical documentation of ICT systems and security solutions with a non-technical description (Consistent non-technical description and business continuity policy, which includes ICT business continuity plans as well as ICT response and recovery plans).</li>
<li>Procedures for segregating crypto assets and customer funds.</li>
<li>Complaint handling procedures.</li>
<li>Cryptoasset custody policy (Required for custody service plans).</li>
<li>Description of trading platform operating rules (if applicable) &#8211; Platform rules and procedures and market abuse prevention system.</li>
<li>Confirmation of the knowledge and experience of persons providing advice or portfolio management (if we intend to provide crypto-asset advice or crypto-asset portfolio management services) &#8211; Documents confirming the competence and experience of advisors necessary to fulfil their duties.</li>
<li>Indication of the type of crypto assets to which the crypto asset service relates.</li>
<li>Systems and procedures to ensure the availability, authenticity, integrity and confidentiality of data.</li>
<li>Outsourcing policy, including policies on contingency plans and exit strategies, taking into account the scale, nature and scope of the crypto asset services provided.</li>
</ul>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/115.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-6075" src="https://lbkp.pl/wp-content/uploads/2025/03/115.jpg" alt="CASP" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/115.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/115-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/115-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/115-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/115-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/115-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/115-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/115-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Summary</b></h2>
<p>Considering the detail and extent of the information and documents that must be attached to the CASP licence application, there is no doubt that this is a process that requires thorough preparation. Therefore, if you are planning to apply for a MICA licence, please contact us to make sure that your application meets all regulatory requirements! We will gladly help you prepare the relevant documentation and ensure compliance with MiCA regulations, as well as other regulations relevant to, among others, financial entities or those in the crypto-asset industry – in particular, GDPR or DORA.</p><p>The post <a href="https://lbkp.pl/en/obtaining-a-casp-licence-key-information-for-crypto-companies/">Obtaining a CASP licence – key information for crypto companies</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DORA: Register of ICT Contract Information – the Polish Financial Supervision Authority will soon give the ‘I&#8217;m checking’ signal</title>
		<link>https://lbkp.pl/en/6133-2/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 03 Apr 2025 07:29:00 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6133</guid>

					<description><![CDATA[<p>One of the important responsibilities that the DORA regulation imposes on financial entities is to maintain and submit to the Polish Financial Supervision Authority a register of information&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/6133-2/">DORA: Register of ICT Contract Information – the Polish Financial Supervision Authority will soon give the ‘I’m checking’ signal</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>One of the important responsibilities that <b>the DORA regulation</b> imposes on <b>financial entities</b> is to <b>maintain and submit to the Polish Financial Supervision Authority a register of information on ICT contracts (ROI)</b>.</p>
<p>This register is more than a list of <b>contracts with ICT suppliers</b>. Its purpose is to create a <b>database of</b> key information for <b>ICT risk management</b>. The ROI is intended to <b>map the relationships</b> between the financial entity and its suppliers, providing <b>supervisory bodies with full insight and control</b> over these relationships.</p>
<p>The deadline for preparing and submitting the <b>first ROI to the KNF</b> is approaching. According to the <b>KNF</b>, the first <b>ROI reports</b> will be submitted in <b>April 2025</b> (the exact date will be announced at the beginning of April).</p>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-6015" src="https://lbkp.pl/wp-content/uploads/2025/03/100.jpg" alt="DORA: Rejestr informacji o umowach ICT" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/100.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/100-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/100-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/100-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/100-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/100-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/100-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/100-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></span></p>
<h2><b>Scope of responsibilities and key challenges</b></h2>
<p>In order to prepare the ROI, financial entities will have to collect a range of information, including:</p>
<ul>
<li>Information on specific ICT contracts, including basic information such as the parties, the type of services, the dates of conclusion and validity, as well as more detailed information on the contract value, notice periods, place of service provision or data storage.</li>
<li>LEI numbers of ICT suppliers and subcontractors.</li>
<li>For contracts that support critical or important functions, <b>comprehensive information about the supply chain is necessary.</b></li>
</ul>
<p>For many <b>financial institutions</b>, the key challenge is <b>obtaining data for the ROI register</b>. This information is often not <b>centrally collected</b>, which requires the involvement of various <b>organisational units</b> and <b>external ICT providers</b>, which can delay the process.</p>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-6017" src="https://lbkp.pl/wp-content/uploads/2025/03/102.jpg" alt="DORA: Rejestr informacji o umowach ICT" width="1440" height="450" /></span></p>
<h2>Formal requirements, validation and changing guidelines</h2>
<p>Collecting data is only the first step. The next challenge is to correctly fill in the ROI register in accordance with the requirements of the Polish Financial Supervision Authority (KNF).</p>
<p>The reporting obligation will be fulfilled via the KNF reporting system, using dedicated ROI forms. The register must meet certain standards – incorrect data format, missing required fields or incorrect file name can result in rejection, which means urgent correction and resubmission.</p>
<p>The changing regulatory environment is an additional challenge. Taxonomies, forms and instructions are constantly updated, so financial institutions must follow KNF and EBA guidelines to comply with the latest requirements and avoid problems when submitting the register.</p>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-6018" src="https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4.jpg" alt="DORA: Rejestr informacji o umowach ICT" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-4-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></span></p>
<h2><b>Consolidation of data in capital groups</b></h2>
<p>For <b>capital groups</b>, the <b>consolidation of the ROI register</b> is an additional challenge. A financial entity required to maintain a <b>consolidated ROI</b> must include not only its own <b>contracts with ICT suppliers</b>, but also similar information from its <b>subsidiaries</b> (if they are subject to DORA).</p>
<p>For financial entities, this means the need to:</p>
<p><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <b>Verify</b> whether and to what extent their ROI is subject to consolidation,</p>
<p><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> If they are required to consolidate, <b>obtain data from subsidiaries</b> in time to verify it and enter it in the register.</p>
<p><b>Standardising the way data is reported</b> by individual entities is key to avoiding <b>inconsistencies in the consolidated ROI register</b>.</p>
<p><span style="color: #000000;"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-6016" src="https://lbkp.pl/wp-content/uploads/2025/03/101.jpg" alt="DORA: Rejestr informacji o umowach ICT" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/101.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/101-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/101-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/101-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/101-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/101-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/101-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/101-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></span></p>
<h2><b>How to prepare?</b></h2>
<p>Due to the complexity of the process of preparing a correct ROI, in my opinion, the key to the success of the entire undertaking is the <b>implementation of an internal process for preparing the register</b>, which should include:</p>
<ol>
<li>careful familiarisation with the definitions in DORA and implementing acts, as well as the interpretation of KNF guidelines;</li>
<li><b>for capital groups: </b>identify the entities covered by the register &#8211; determine which entities within the financial group are subject to the reporting obligation;</li>
<li><b>collect and complete data</b> in the appropriate forms &#8211; identify missing information and contact suppliers to obtain it.</li>
<li><b>comply with formats and taxonomy</b></li>
<li><b>Regularly monitoring regulatory</b> changes – keeping track of updates from the KNF and EBA to ensure that the organisation is working on the correct forms and in accordance with current guidelines.</li>
</ol>
<h2><b>o summarise&#8230;</b></h2>
<p>The ICT Contract Information Register is a <b>key obligation for financial entities covered by DORA</b>, and its preparation requires time, special care and precision. Failure to comply with the PFSA&#8217;s requirements may result in the report being rejected and, in extreme cases, severe sanctions.</p>
<p>Financial institutions should work intensively on their records and also <b>monitor updates provided by the PFSA and EBA, </b>as changing guidelines may force additional adjustments in reporting.</p>
<p><b>Useful materials</b></p>
<ul>
<li><b>EBA:</b><a href="https://www.eba.europa.eu/activities/direct-supervision-and-oversight/digital-operational-resilience-act/preparation-dora-application">Guidelines and materials regarding DORA</a></li>
<li><b>KNF:</b> <a href="https://crp.knf.gov.pl/">DORA reporting portal</a> (reporting forms, detailed instructions and KNF guidelines, requires login)</li>
</ul><p>The post <a href="https://lbkp.pl/en/6133-2/">DORA: Register of ICT Contract Information – the Polish Financial Supervision Authority will soon give the ‘I’m checking’ signal</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Data protection violations – what do you need to know?</title>
		<link>https://lbkp.pl/en/6080-2/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 31 Mar 2025 12:24:17 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=6080</guid>

					<description><![CDATA[<p>In today&#8217;s digital world, data protection is becoming an increasingly important topic. Every organisation that processes personal data must be prepared for potential data breaches and know how&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/6080-2/">Data protection violations – what do you need to know?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>In today&#8217;s digital world, data protection is becoming an increasingly important topic. Every organisation that processes personal data must be prepared for potential data breaches and know how to proceed in such a situation. In this article, we will discuss the most important issues related to personal data breaches in the light of the GDPR based on the publication of the UODO (Polish Data Protection Authority) entitled ‘Guide under the GDPR &#8211; obligations of administrators related to personal data breaches v2’.</p>
<p><a href="https://lbkp.pl/wp-content/uploads/2025/03/93.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5944" src="https://lbkp.pl/wp-content/uploads/2025/03/93.jpg" alt="Poradnik na gruncie RODO" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/93.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/93-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/93-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/93-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/93-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/93-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/93-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/93-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></p>
<h2><b>What is a data breach?</b></h2>
<p>A data breach is a security incident that leads to accidental or unlawful:</p>
<ul>
<li>data destruction</li>
<li>data loss</li>
<li>data modification</li>
<li>unauthorised disclosure of data</li>
<li>unauthorised access to data</li>
</ul>
<p>A breach can be both a deliberate action (e.g. a cyber attack) and an accidental event (e.g. losing a data carrier). The key point is that the breach concerns personal data being processed and can have a negative impact on the rights and freedoms of the data subjects.</p>
<h2><b>Why are breaches dangerous?</b></h2>
<p>Data breaches can have serious consequences for data subjects, such as:</p>
<ul>
<li>physical injury</li>
<li>property damage (e.g. identity theft, financial fraud)</li>
<li>non-pecuniary damage (e.g. damage to reputation, mental stress)</li>
</ul>
<p>Even seemingly insignificant incidents can have far-reaching consequences. It is therefore important that data controllers respond appropriately to any violations.</p>
<h2><b>Who is responsible for data protection?</b></h2>
<p>The main responsibility lies with the data controller, i.e. the entity that determines the purposes and means of processing personal data. It is the controller who must implement appropriate technical and organisational measures to ensure data security.</p>
<p>The following also play an important role:</p>
<ul>
<li>Processors &#8211; process data on behalf of the controller</li>
<li>Data Protection Officers (DPO) &#8211; advise and monitor compliance with the GDPR</li>
</ul>
<h2><b>What are the responsibilities of the controller?</b></h2>
<p>In the context of personal data breaches, the controller has the following responsibilities:</p>
<ol>
<li>Preventing breaches by implementing appropriate safeguards</li>
<li>Detecting and identifying breaches</li>
<li>Responding to breaches:</li>
<li>Remediation of the breach and minimisation of its effects</li>
<li>Assessment of the risk associated with the breach</li>
<li>Reporting of the breach to the supervisory authority (if there is a risk)</li>
<li>Notification of the data subjects (in case of high risk)</li>
<li>Documentation of the breach</li>
</ol>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/96.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5947" src="https://lbkp.pl/wp-content/uploads/2025/03/96.jpg" alt="dane osobowe" width="1440" height="450" /></a></span></p>
<h2><b>How can data breaches be prevented?</b></h2>
<p>The key is to implement appropriate technical and organisational measures, such as:</p>
<ul>
<li>Data encryption and pseudonymisation</li>
<li>Regular testing and evaluation of the effectiveness of security measures</li>
<li>Employee training</li>
<li>Incident response procedures</li>
<li>Control of data access</li>
<li>Data backups</li>
</ul>
<p>The selection of measures should be based on an analysis of the risks associated with the processing.</p>
<h2><b>How to detect violations?</b></h2>
<p>Administrators should implement monitoring and incident detection systems, such as:</p>
<ul>
<li>Intrusion detection systems (IDS/IPS)</li>
<li>Anti-virus software</li>
<li>Analysis of system logs</li>
<li>Procedures for reporting incidents by employees</li>
</ul>
<p>It is also important to train staff to recognise potential violations.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/97.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5948" src="https://lbkp.pl/wp-content/uploads/2025/03/97.jpg" alt="dane osobowe" width="1440" height="450" /></a></span></p>
<h2><b>What to do after a breach has been detected?</b></h2>
<p>After a breach has been detected, the controller should:</p>
<ol>
<li>Take immediate action to contain the breach and minimise its impact</li>
<li>Assess the risk to the rights and freedoms of data subjects</li>
<li>Report the breach to the supervisory authority within 72 hours if there is a risk (unless it can be demonstrated that the risk is unlikely to materialise)</li>
<li>Notify the data subjects if there is a high risk</li>
<li>Document the breach and the measures taken</li>
</ol>
<h2><b>Reporting breaches to the supervisory authority</b></h2>
<p>The notification to the President of the Personal Data Protection Office should include:</p>
<ul>
<li>A description of the nature of the breach</li>
<li>The categories and approximate number of data subjects</li>
<li>The possible consequences of the breach</li>
<li>The measures taken to remedy the breach</li>
<li>The contact details of the Data Protection Officer or other contact point</li>
</ul>
<p>The notification can be made electronically via a dedicated form or ePUAP.</p>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/94.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5945" src="https://lbkp.pl/wp-content/uploads/2025/03/94.jpg" alt="dane osobowe" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/94.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/94-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/94-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/94-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/94-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/94-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/94-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/94-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Notification of data subjects</b></h2>
<p>In the event of a high risk, the controller must notify the data subjects without undue delay. The notification should:</p>
<ul>
<li>Be written in simple and clear language</li>
<li>Describe the nature of the breach</li>
<li>Include the contact details of the DPO or other contact point</li>
<li>Describe the possible consequences of the breach</li>
<li>Describe the measures taken to remedy the breach</li>
<li>Include recommendations for individuals to minimise potential negative effects</li>
</ul>
<p>Notifications can be made directly (e.g. by email) or through a public announcement.</p>
<h2><b>Documenting breaches</b></h2>
<p>The controller must document all violations, regardless of whether they were reported. The documentation should include:</p>
<ul>
<li>The circumstances of the violation</li>
<li>Its effects</li>
<li>The remedial measures taken</li>
<li>The reasoning behind the decision regarding the report/notification</li>
<li>The documentation serves as proof of compliance with the GDPR and may be subject to inspection by the supervisory authority.</li>
</ul>
<p><span style="color: #000000;"><a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5.jpg"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-5949" src="https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5.jpg" alt="dane osobowe" width="1440" height="450" srcset="https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5.jpg 1440w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-300x94.jpg 300w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-1024x320.jpg 1024w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-768x240.jpg 768w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-370x116.jpg 370w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-840x263.jpg 840w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-410x128.jpg 410w, https://lbkp.pl/wp-content/uploads/2025/03/Grafiki-na-strone-5-730x228.jpg 730w" sizes="(max-width: 1440px) 100vw, 1440px" /></a></span></p>
<h2><b>Cross-border personal data breaches</b></h2>
<p>A cross-border data breach is an incident that involves the processing of personal data in more than one member state of the European Union. This can be because the controller or processor has organisational units in several EU countries, or when the breach affects data subjects in different member states.</p>
<p>In the case of cross-border data breaches, the incident reporting and management process becomes more complex. Controllers must cooperate with supervisory authorities in different countries and also take into account differences in local regulations and procedures. It is crucial to quickly determine which supervisory authority is the lead authority in a given case and to ensure effective communication between all parties involved. The cross-border nature of the breach can also affect the risk assessment and the way in which data subjects are notified, especially when it is necessary to take into account cultural and linguistic differences in different countries.</p>
<h2><b>Summary</b></h2>
<p>Responding appropriately to personal data breaches is crucial to protecting the rights of data subjects. This requires controllers to:</p>
<ul>
<li>Implement appropriate safeguards</li>
<li>Prepare incident response procedures</li>
<li>Act quickly in the event of a breach</li>
<li>Communicate transparently with the supervisory authority and data subjects</li>
</ul>
<p>Remember that the main purpose of these measures is to protect the rights and freedoms of individuals, not to avoid penalties. A responsible approach to data protection builds trust and minimises the negative effects of possible violations.</p>
<h2><b>Want to know more? </b></h2>
<p>Read the new guide from the UODO (the Polish Data Protection Authority):</p>
<p><a href="https://uodo.gov.pl/pl/138/3561">https://uodo.gov.pl/pl/138/3561</a></p>
<p><span style="color: #000000;" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> <a style="color: #000000;" href="https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58.png"><img loading="lazy" decoding="async" class="wp-image-5950 alignleft" src="https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58.png" alt="Poradnik UODO" width="228" height="322" srcset="https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58.png 1038w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-212x300.png 212w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-724x1024.png 724w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-768x1086.png 768w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-370x523.png 370w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-840x1188.png 840w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-410x580.png 410w, https://lbkp.pl/wp-content/uploads/2025/03/Zrzut-ekranu-2025-03-11-o-12.49.58-730x1032.png 730w" sizes="(max-width: 228px) 100vw, 228px" /></a></span></p>
<h2><b>What&#8217;s new in the guide?</b></h2>
<p>The new version takes into account the latest interpretations of regulations, case law and practical tips that will help administrators make the right decisions in the event of a personal data breach. It includes, among others:</p>
<ul>
<li>updated procedures for responding to breaches (reporting to the President of the Personal Data Protection Office);</li>
<li>practical examples and case studies;</li>
<li>guidelines on cooperation with the President of the Personal Data Protection Office and other supervisory authorities;</li>
<li>key recommendations on risk assessment and breach prevention.</li>
</ul>
<p><span style="color: #000000;" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335559685&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></p><p>The post <a href="https://lbkp.pl/en/6080-2/">Data protection violations – what do you need to know?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DORA on the horizon: key changes for the financial sector 🏦</title>
		<link>https://lbkp.pl/en/dora-on-the-horizon-key-changes-for-the-financial-sector-%f0%9f%8f%a6/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 08 Aug 2024 07:37:13 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=3686</guid>

					<description><![CDATA[<p>DORA &#8211; new standards for cyber security 🔒 In the digital age, when most financial transactions take place online, the security of our data and funds is becoming&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/dora-on-the-horizon-key-changes-for-the-financial-sector-%f0%9f%8f%a6/">DORA on the horizon: key changes for the financial sector 🏦</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-3681" src="https://lbkp.pl/wp-content/uploads/2024/08/1723019185629.png" alt="" width="1280" height="720" srcset="https://lbkp.pl/wp-content/uploads/2024/08/1723019185629.png 1280w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-300x169.png 300w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-1024x576.png 1024w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-768x432.png 768w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-370x208.png 370w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-840x473.png 840w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-410x231.png 410w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-730x411.png 730w, https://lbkp.pl/wp-content/uploads/2024/08/1723019185629-270x152.png 270w" sizes="(max-width: 1280px) 100vw, 1280px" /></p>
<p>DORA &#8211; new standards for cyber security <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f512.png" alt="🔒" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>In the digital age, when most financial transactions take place online, the security of our data and funds is becoming a priority. We&#8217;ve all seen recently &#8211; with the example of Microsoft&#8217;s operating systems crashing &#8211; what happens when one of the more commonly used online services for business, Office 365, is affected. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2708.png" alt="✈" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6ab.png" alt="🚫" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Airline connections were cancelled, the London Stock Exchange did not work, and bank customers also reported problems (in Poland, Santander Bank and PKO BP, among others, were affected). Microsoft estimated that up to 8.5 million Windows devices were affected by the incident. The effects of what turned out to be &#8216;just&#8217; a crash brought part of the world to a halt for a moment. The scale of the disruption to the operations of entities in many industries makes one wonder what might happen when we are dealing not with a crash, but with a successful cyber-attack. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f914.png" alt="🤔" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4bb.png" alt="💻" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>The European Union, recognising the growing risks in the area of digital security for the financial sector and its customers, in December 2023 enacted the Digital Operational Resilience Act (DORA for short), which sets new standards for the cyber-security of financial entities, aiming to ensure their resilience to all ICT-related disruptions and threats. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f310.png" alt="🌐" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dc.png" alt="📜" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-3680" src="https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1.png" alt="" width="1414" height="2000" srcset="https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1.png 1414w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-212x300.png 212w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-724x1024.png 724w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-768x1086.png 768w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-1086x1536.png 1086w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-370x523.png 370w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-840x1188.png 840w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-410x580.png 410w, https://lbkp.pl/wp-content/uploads/2024/08/Wykres-1-730x1033.png 730w" sizes="(max-width: 1414px) 100vw, 1414px" /></p>
<p><strong>The new regulations aim to:</strong></p>
<p>Minimise the risks associated not only with cyber attacks, but more broadly with security incidents. By establishing uniform standards and procedures, DORA is expected to contribute to protecting the integrity, security and continuity of financial services in the European Union. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="🛡" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f1ea-1f1fa.png" alt="🇪🇺" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><strong>The countdown is on <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/23f3.png" alt="⏳" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></p>
<p>Financial entities have until 17 January 2025 to comply with DORA. After this date, there will be no concessionary tariffs &#8211; the FSA, during trainings and meetings with the financial sector, warns that it will not wait for latecomers and plans to verify and enforce the implementation of the new obligations from day one. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4c5.png" alt="📅" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="🔍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>Importantly, DORA is not a directive (as is the case with another cyber-security-relevant act such as NIS2), but a regulation. This means that it is binding in its entirety on the entities to which it is addressed and is directly applicable in all countries of the European Union, without the need to implement it into local legal orders by means of laws. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4dc.png" alt="📜" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2696.png" alt="⚖" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><strong>Who is affected by DORA?</strong> <strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3e6.png" alt="🏦" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4bc.png" alt="💼" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></p>
<p>DORA primarily &#8211; but not exclusively &#8211; covers a broad spectrum of financial institutions and digital finance entities. Among others, banks, insurance companies, investment funds, credit institutions, cryptocurrency providers, e-money institutions and other financial services providers are obliged to comply with the new regulations. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b3.png" alt="💳" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3e2.png" alt="🏢" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>In addition, DORA introduces certain obligations for technology providers, including cloud service providers and other ICT service providers. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2601.png" alt="☁" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4bb.png" alt="💻" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><strong>What does DORA mean for the financial sector?</strong> <strong><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ca.png" alt="📊" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f512.png" alt="🔒" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></p>
<p>DORA imposes obligations on financial sector players, requiring financial institutions not only to respond to incidents, but also to take a number of preventive measures, based on the principle that prevention is better than cure. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4a1.png" alt="💡" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f527.png" alt="🔧" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>In practice, this means taking action primarily in the following key areas:</p>
<ol>
<li><strong>ICT risk management</strong> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f5a5.png" alt="🖥" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" />Instytucje finance should develop and implement a comprehensive ICT risk management strategy. This strategy should include identifying, assessing, monitoring and controlling ICT risks to ensure the security and integrity of IT systems.</li>
<li><strong>ICT incident management</strong> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="🛡" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png" alt="🚨" class="wp-smiley" style="height: 1em; max-height: 1em;" />Classification and reporting of ICT incidents are key to effective security management, according to DORA. Financial institutions will be required to follow clear guidelines for incident classification, which is expected to lead to appropriate tracking, analysis and response.Responsibilities in this area will include, but are not limited to:Creating and implementing uniform incident classification guidelines to categorise incidents by level of severity and type of threat.Regular reporting of incidents to relevant authorities and stakeholders, in accordance with applicable standards and regulations.Conducting root cause analysis of incidents to identify vulnerabilities and implement corrective actions.</li>
<li><strong>Risk management from external ICT service providers</strong> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f91d.png" alt="🤝" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="🔍" class="wp-smiley" style="height: 1em; max-height: 1em;" />Financial institutions should define policies for managing cooperation with external ICT service providers. Responsibilities in this area will include, among other things, developing criteria for the evaluation and selection of ICT service providers to ensure that they meet security and compliance requirements, ensuring that contracts entered into with ICT providers comply with the requirements set by DORA, and regularly monitoring and evaluating the performance of providers.</li>
<li><strong>Operational digital resilience testing</strong> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f504.png" alt="🔄" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" />Obowiązki in this area will include, among other things, the establishment of a comprehensive operational digital resilience testing programme. Financial entities other than micro-enterprises will be required to test all ICT systems and applications at least once a year. For some obliged entities, DORA also provides for an additional obligation to carry out advanced penetration testing (TLPT) for threat searches at least every 3 years.</li>
</ol>
<p><strong>Where there are obligations, there are also sanctions <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2696.png" alt="⚖" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b0.png" alt="💰" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></p>
<p>Understanding and adapting to the requirements of DORA are essential from the point of view of financial actors, not only for the need to ensure an adequate level of operational digital resilience, but also to avoid serious legal and financial consequences.</p>
<p>DORA implies that the competent authorities (in Poland this will primarily be the FSA) will be granted broad powers to supervise and enforce DORA. They will be entitled to request access to any documents and data they deem relevant in the context of their investigations. Financial institutions must be prepared for possible audits and inspections. Failure to cooperate or provide the requested information may lead to additional sanctions. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f50d.png" alt="🔍" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>In the event of violations of DORA, various administrative sanctions may be applied by the supervisory authorities. These include, inter alia, cease and desist orders for non-compliant activities, the requirement to terminate practices contrary to the regulations and the application of financial sanctions aimed at enforcing compliance. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4bc.png" alt="💼" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4b8.png" alt="💸" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><strong>Summary <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4ca.png" alt="📊" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/270d.png" alt="✍" class="wp-smiley" style="height: 1em; max-height: 1em;" /></strong></p>
<p>Of course, a full assessment of the impact of the new regulations will only be possible after some time, but we already dare to hypothesise that DORA is a milestone towards ensuring digital operational resilience in the EU financial sector. With the introduction of new ICT risk management standards and the requirement for a proactive approach to digital security, DORA should not only help protect financial institutions, but also increase customer confidence in financial services. The move is now on the side of the financial sector &#8211; achieving the goal of DORA and the associated benefits will only be possible if the implementation of the new regulations is taken seriously. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f51c.png" alt="🔜" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f527.png" alt="🔧" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p><p>The post <a href="https://lbkp.pl/en/dora-on-the-horizon-key-changes-for-the-financial-sector-%f0%9f%8f%a6/">DORA on the horizon: key changes for the financial sector 🏦</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>NIS 2 &#8211; New requirements</title>
		<link>https://lbkp.pl/en/nis-2-new-requirements/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Wed, 31 Jul 2024 12:14:16 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbplegal.com/?p=3660</guid>

					<description><![CDATA[<p>The end of 2024 is not only marked by whistleblowers, but also by ‘Cyber Security’. We owe this to the NIS 2 directive and the DORA regulation. Today,&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/nis-2-new-requirements/">NIS 2 – New requirements</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><img loading="lazy" decoding="async" class="alignnone wp-image-3657" src="https://lbkp.pl/wp-content/uploads/2024/07/1722418116060.jpg" alt="" width="390" height="327" srcset="https://lbkp.pl/wp-content/uploads/2024/07/1722418116060.jpg 1832w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-300x252.jpg 300w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-1024x859.jpg 1024w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-768x644.jpg 768w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-1536x1288.jpg 1536w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-370x310.jpg 370w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-840x704.jpg 840w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-410x344.jpg 410w, https://lbkp.pl/wp-content/uploads/2024/07/1722418116060-730x612.jpg 730w" sizes="(max-width: 600px) 100vw, 390px" /></p>
<p>The end of 2024 is not only marked by whistleblowers, but also by ‘Cyber Security’. We owe this to the NIS 2 directive and the DORA regulation. Today, a few words about NIS 2.</p>
<p>By 17 October 2024, Poland must implement the EU NIS 2 Directive, which is intended to ensure the resilience of entities important from a public interest perspective to cyber threats. This requires the implementation of appropriate procedures and training, <a href="/%E2%80%98http://m.in/%E2%80%99">including</a>: risk analysis and IT system security, incident handling, business continuity, crisis management, supply chain security and others.<br />
NIS 2 will cover a number of entities that have not yet been regulated under NIS 1. According to the draft amendments to the National Cyber Security System Act (UKSC), entities that should be particularly interested in NIS 2 <a href="/%E2%80%98http://m.in/%E2%80%99">include</a>:<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Energy<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Transport<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Banking<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Infrastructure financial markets<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Protection health<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Supply drinking water and its distribution<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Digital infrastructure<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Wastewater<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Management IT services<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Public sector<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Space<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Postal and courier services<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Waste management<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> production manufacturing and distribution of chemicals<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Production food processing and distribution<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Production<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Providers of digital services<br />
<img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Scientific research</p>
<p>The list is long <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f60a.png" alt="😊" class="wp-smiley" style="height: 1em; max-height: 1em;" />. What&#8217;s more, the UKSC draft requires self-identification of entities that meet the criteria and registration in the relevant register.<br />
The UKSC amendment, according to the draft, will come into force within one month of publication. This will not be sufficient time to fully implement the new obligations. Therefore, we are already proposing to audit and implement NIS 2 for our clients, based on the PN-EN ISO/IEC 27001, PN-EN ISO/IEC 22301 standards and market best practices. Once the legislation has been finalised, fine-tuning the procedures will be sufficient.</p>
<p>And you, are you ‘catching on’ to NIS2 and are you NIS-ready?</p><p>The post <a href="https://lbkp.pl/en/nis-2-new-requirements/">NIS 2 – New requirements</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
