<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kancelaria LBKP</title>
	<atom:link href="https://lbkp.pl/en/feed/" rel="self" type="application/rss+xml" />
	<link>https://lbkp.pl</link>
	<description>Doradztwo prawne NewTech, RODO, cyberbezpieczeństwo, e-commerce, IP, M&#38;A, nieruchomości. PL, EN, DE, IT, ES, UA, RU.</description>
	<lastBuildDate>Thu, 20 Aug 2026 10:19:49 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://lbkp.pl/wp-content/uploads/2024/02/sygnet-rgb-2-e1755872238786-100x100.png</url>
	<title>Kancelaria LBKP</title>
	<link>https://lbkp.pl</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The customer blacklist. When can a company use it, and when does it bring trouble upon itself?</title>
		<link>https://lbkp.pl/en/the-customer-blacklist-when-can-a-company-use-it-and-when-does-it-bring-trouble-upon-itself/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 10:19:46 +0000</pubDate>
				<category><![CDATA[Commercial, Corporate & Compliance en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48708</guid>

					<description><![CDATA[<p>The customer blacklist: When can a company use it? Discover the legal risks under GDPR, consumer rights, and lessons from the Hotel Gołębiewski case.</p>
<p>The post <a href="https://lbkp.pl/en/the-customer-blacklist-when-can-a-company-use-it-and-when-does-it-bring-trouble-upon-itself/">The customer blacklist. When can a company use it, and when does it bring trouble upon itself?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<!-- START TABLE OF CONTENTS -->
<nav class="lbkp-toc-box" aria-label="Table of Contents">
  <div class="lbkp-toc-header">
    <span class="lbkp-toc-title">Table of Contents</span>
  </div>
  <ol class="lbkp-toc-list">
    <li><a href="#czym-jest-czarna-lista">What is a customer blacklist in practice, versus in the eyes of the law?</a></li>
    <li><a href="#trzy-rezimy-prawne">Three legal regimes to bear in mind simultaneously</a></li>
    <li><a href="#gdzie-lezy-ryzyko">Where lies the risk, and where the real benefit?</a></li>
    <li><a href="#kiedy-teoria-spotyka-praktyke">When theory meets practice: The Hotel Gołębiewski case</a></li>
    <li><a href="#wnioski-praktyczne">Practical conclusions</a></li>
  </ol>
</nav>

<style>
  @import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');

  p {
    margin-bottom: 1.25em !important;
    line-height: 1.7 !important;
  }

  h2 {
    margin-top: 2em !important;
    margin-bottom: 0.8em !important;
  }

  .lbkp-toc-box {
    font-family: 'Roboto', sans-serif;
    background: #f4f6ff;
    border-left: 4px solid #0E20EC;
    padding: 24px 28px;
    margin: 32px 0;
    border-radius: 0 12px 12px 0;
    box-shadow: 0 2px 12px rgba(14, 32, 236, 0.06);
  }

  .lbkp-toc-header {
    margin-bottom: 16px;
  }

  .lbkp-toc-title {
    font-weight: 700;
    font-size: 0.85rem;
    color: #0E20EC;
    text-transform: uppercase;
    letter-spacing: 1.2px;
  }

  .lbkp-toc-list {
    margin: 0;
    padding-left: 20px;
    list-style-type: decimal;
  }

  .lbkp-toc-list li {
    margin-bottom: 10px;
    line-height: 1.6;
    font-size: 0.95rem;
  }

  .lbkp-toc-list li::marker {
    font-weight: 700;
    color: #0E20EC;
  }

  .lbkp-toc-list li:last-child {
    margin-bottom: 0;
  }

  .lbkp-toc-list a {
    color: #1e293b;
    text-decoration: none;
    font-weight: 400;
    display: inline-block;
    transition: all 0.2s cubic-bezier(0.4, 0, 0.2, 1);
  }

  .lbkp-toc-list a:hover {
    color: #0E20EC;
    font-weight: 500;
    transform: translateX(4px);
  }
</style>
<!-- END TABLE OF CONTENTS -->



<p class="wp-block-paragraph">Can a company put a customer on an undesirable persons list after they publish a critical review of its services? This is a question that many entrepreneurs and consumers have been asking themselves in recent weeks, triggered by the high-profile case of one Polish hotel. The answer requires looking at several independent legal regimes simultaneously – and taking into account that neither party to such a dispute is automatically in the right.</p>



<h4 class="wp-block-heading">What is a customer blacklist in practice, versus in the eyes of the law?</h4>



<p class="wp-block-paragraph">In practice, it is often nothing formalized, such as a note in a booking system or just a verbal instruction passed to the reception shift, which is enough to ensure a customer is no longer welcome. The reasons can be clear-cut, such as theft or aggression towards staff, but just as often they are subjective, such as a dispute over a bill, a conflict with service personnel, and sometimes&#8230; simply an inconvenient review online.</p>



<p class="wp-block-paragraph">The problem affects not only hotel services. It also occurs on the internet, for example in shops looking for ways to deal with customers who, in their view, abuse the right of withdrawal, return damaged goods, and expect a refund.</p>



<p class="wp-block-paragraph">From a legal perspective, however, this is not just an ordinary office memo; it is a set of personal data. This means that its existence, purpose, and storage period are subject to exactly the same rigours as any other data processing within a company. What looks like a simple precautionary measure to a manager is, under data protection regulations, an operation requiring a separate legal basis and a clear time limit.</p>



<h4 class="wp-block-heading">Three legal regimes to bear in mind simultaneously</h4>



<p class="wp-block-paragraph">The GDPR does not recognize the concept of storing data &#8220;just in case&#8221;. In accordance with the principles of purpose limitation and storage limitation (Article 5(1)(b) and (e) of the GDPR), data can only be processed for as long as a specific, current purpose exists, and the basis for the entry is usually the legitimate interest of the controller (Article 6(1)(f) of the GDPR). This interest must, however, realistically outweigh the rights of the data subject – the mere fact of a conflict with a customer is not enough. Consumer law operates separately. Freedom of contract (Article 353¹ of the Civil Code) does not mean arbitrary freedom in refusing service, so a refusal without a specific justification previously outlined in the terms and conditions carries the risk of allegations of consumer rights violations, and in extreme cases, even discrimination.</p>



<p class="wp-block-paragraph">Another layer is personal rights, meaning the relationship between the consumer&#8217;s right to criticism and the entrepreneur&#8217;s right to protection of good name, protected under Articles 23 and 24 of the Civil Code in conjunction with Article 43 of the Civil Code, applied mutatis mutandis to legal persons. A company may defend its reputation, but substantive criticism falling within the limits of permissible service evaluation does not constitute an unlawful violation of personal rights, even if it is inconvenient for the company.</p>



<p class="wp-block-paragraph">On top of all this comes a thread that is only just emerging: automation. An increasing number of companies support the management of problematic customer registries with scoring systems that flag accounts as risky based on the number of complaints or behavioral patterns. If such a decision is made fully automatically and produces a tangible legal effect for the customer, Article 22 of the GDPR comes into play, limiting the permissibility of such decisions and requiring human intervention. The AI Act itself does not classify the maintenance of a customer list as a high-risk system, but if tools that systematically assess the behavior of natural persons are used to create it, it is worth checking already at the implementation stage whether it approaches a category subject to additional transparency obligations.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="674" src="https://lbkp.pl/wp-content/uploads/2026/08/14869-1-1024x674.jpg" alt="" class="wp-image-48709" srcset="https://lbkp.pl/wp-content/uploads/2026/08/14869-1-1024x674.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-300x198.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-768x506.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-1536x1011.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-370x244.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-840x553.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1-410x270.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/08/14869-1.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading">Where lies the risk, and where the real benefit?</h4>



<p class="wp-block-paragraph">The registry of undesirable persons itself is not prohibited and is often fully justified, because the protection of staff, property, and other customers is a legitimate interest of the entrepreneur. Trouble begins only when it is run without clear rules. Most often, companies fail to define the purpose and retention period of data, treat criticism or a complaint as an automatic basis for an entry without determining whether a breach of rules actually occurred, extend the ban to third parties who were not party to the dispute, or stop at vague regulatory provisions instead of a closed catalogue of refusal grounds. A well-designed registry has a clear purpose, a specific catalogue of events, and a defined data retention period; only then does it become an effective tool for protecting the business rather than a source of additional risk.</p>



<h4 class="wp-block-heading">When theory meets practice: The Hotel Gołębiewski case</h4>



<p class="wp-block-paragraph">A good, recent example is the high-profile case of Hotel Gołębiewski and Szymon Nyczke, a YouTuber known as Książulo. It all started with an ordinary consumer dispute. Faulty air conditioning in a newly opened suite costing nearly PLN 5,000 per night, bedroom temperatures reaching over 32 degrees Celsius, and yellow water with sediment. Gołębiewski Holding admitted that such a situation should not have happened and honored the complaint by refunding the stay, while the Office of Competition and Consumer Protection (UOKiK) directly referred to the case on Instagram, pointing to Książulo&#8217;s stance as an example of enforcing consumer rights.</p>



<p class="wp-block-paragraph">A few days later, the matter took a completely different turn. A letter was sent to the network&#8217;s facility directors indicating that Książulo and accompanying persons had been entered onto the list of undesirable guests, covering accommodation, restaurants, and water parks. Upon attempting to make a reservation, reception refused, citing a violation of the facility&#8217;s rules without specifying what that violation was supposed to be. The ban was lifted the same day following intervention by the management and the network&#8217;s owner, Jarosław Gołębiewski, and the chain has yet to publicly present a detailed stance on the list itself.</p>



<p class="wp-block-paragraph">It is hard to find a better illustration of the mistakes described above. The lack of a clear purpose and retention period for the entry, treating a critical material as an event justifying a ban without establishing whether the regulations were actually breached, and extending the ban to accompanying persons who were not party to any dispute. However, the case is not exclusively unfavorable to the hotel. Jarosław Gołębiewski assessed Książulo&#8217;s material as harmful, and the creator himself emphasized that he did not wish to wage a campaign against the hotel – which clearly shows that justified consumer criticism and the protection of an entrepreneur&#8217;s good name are two independent threads requiring separate legal assessment. They cannot be resolved with a single hasty entry on a list.</p>



<h4 class="wp-block-heading">Practical conclusions</h4>



<p class="wp-block-paragraph">Maintaining a registry of undesirable persons is not inherently impermissible, but it requires meeting several conditions simultaneously. There must be a specific event forming the basis of the entry, a clearly defined purpose and retention period for the data, restriction of the entry solely to the person actually involved in the event, and a precise catalogue of service refusal grounds in the terms and conditions rather than vague reservations. The Hotel Gołębiewski case clearly demonstrates how quickly a lack of such rules can turn a simple consumer dispute into a legal issue encompassing the GDPR, consumer rights, and personal rights all at once. It is worth checking this in advance, rather than only when the topic hits the media – especially where automated customer profiling by scoring systems is involved, which additionally requires evaluation under Article 22 of the GDPR and the AI Act.</p>



<p class="wp-block-paragraph">If you run a service company and wonder whether your terms and conditions and internal procedures comply with the GDPR and consumer law, contact us. We will help you verify it.</p><p>The post <a href="https://lbkp.pl/en/the-customer-blacklist-when-can-a-company-use-it-and-when-does-it-bring-trouble-upon-itself/">The customer blacklist. When can a company use it, and when does it bring trouble upon itself?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>UODO takes a closer look at mailboxes. UODO takes a closer look at mailboxes. Not because you store too many emails. Because every additional message increases the risk.</title>
		<link>https://lbkp.pl/en/uodo-takes-a-closer-look-at-mailboxes-uodo-takes-a-closer-look-at-mailboxes-not-because-you-store-too-many-emails-because-every-additional-message-increases-the-risk/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 09:01:37 +0000</pubDate>
				<category><![CDATA[NewTech Law en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48680</guid>

					<description><![CDATA[<p>Discover key insights from the latest UODO guidelines on email security. Learn how data retention, MFA, and practical safeguards can protect your organization during an audit.</p>
<p>The post <a href="https://lbkp.pl/en/uodo-takes-a-closer-look-at-mailboxes-uodo-takes-a-closer-look-at-mailboxes-not-because-you-store-too-many-emails-because-every-additional-message-increases-the-risk/">UODO takes a closer look at mailboxes. UODO takes a closer look at mailboxes. Not because you store too many emails. Because every additional message increases the risk.</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<!-- START TABLE OF CONTENTS -->
<nav class="lbkp-toc-box" aria-label="Table of Contents">
  <div class="lbkp-toc-header">
    <span class="lbkp-toc-title">Table of Contents</span>
  </div>
  <ol class="lbkp-toc-list">
    <li><a href="#archiwum-mailowe-a-ryzyko">The larger the archive, the greater the risk</a></li>
    <li><a href="#rozwiazania-techniczne-i-organizacyjne">Specific technical and organisational solutions</a></li>
    <li><a href="#znaczenie-z-perspektywy-rozliczalnosci">Significance from the accountability perspective</a></li>
    <li><a href="#praktyczna-lista-dzialan">Practical checklist of actions to verify</a></li>
  </ol>
</nav>

<style>
  @import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');

  p {
    margin-bottom: 1.25em !important;
    line-height: 1.7 !important;
  }

  h2 {
    margin-top: 2em !important;
    margin-bottom: 0.8em !important;
  }

  .lbkp-toc-box {
    font-family: 'Roboto', sans-serif;
    background: #f4f6ff;
    border-left: 4px solid #0E20EC;
    padding: 24px 28px;
    margin: 32px 0;
    border-radius: 0 12px 12px 0;
    box-shadow: 0 2px 12px rgba(14, 32, 236, 0.06);
  }

  .lbkp-toc-header {
    margin-bottom: 16px;
  }

  .lbkp-toc-title {
    font-weight: 700;
    font-size: 0.85rem;
    color: #0E20EC;
    text-transform: uppercase;
    letter-spacing: 1.2px;
  }

  .lbkp-toc-list {
    margin: 0;
    padding-left: 20px;
    list-style-type: decimal;
  }

  .lbkp-toc-list li {
    margin-bottom: 10px;
    line-height: 1.6;
    font-size: 0.95rem;
  }

  .lbkp-toc-list li::marker {
    font-weight: 700;
    color: #0E20EC;
  }

  .lbkp-toc-list li:last-child {
    margin-bottom: 0;
  }

  .lbkp-toc-list a {
    color: #1e293b;
    text-decoration: none;
    font-weight: 400;
    display: inline-block;
    transition: all 0.2s cubic-bezier(0.4, 0, 0.2, 1);
  }

  .lbkp-toc-list a:hover {
    color: #0E20EC;
    font-weight: 500;
    transform: translateX(4px);
  }
</style>
<!-- END TABLE OF CONTENTS -->



<p class="wp-block-paragraph">For most businesses, the mailbox has long ceased to be merely a communication tool. It has become an archive of business knowledge. This is precisely where client arrangements, project histories, management board decisions, and case documentation are kept. From a business perspective, it is hardly surprising that organisations are reluctant to delete such information.</p>



<h2 class="wp-block-heading">The larger the archive, the greater the risk</h2>



<p class="wp-block-paragraph">The problem is that almost every such message also contains personal data. The larger the archive, the wider the scope of data that could be exposed in the event of mailbox takeover, employee error, or a cyberattack. Therefore, data retention is not merely an obligation arising from the GDPR; it is also one of the fundamental mechanisms for limiting the impact of a potential security incident.</p>



<p class="wp-block-paragraph">This is, of course, nothing new. The principle of limiting the storage period for personal data has been in force for years. What is new, however, is that the President of the Personal Data Protection Office (UODO), in his latest bulletin, practically demonstrates how to secure mailboxes in situations where an organisation, for various reasons, stores messages longer than would be optimal.</p>



<h2 class="wp-block-heading">Specific technical and organisational solutions</h2>



<p class="wp-block-paragraph">The authority does not limit itself to reminding organisations of their obligations under the GDPR. It points to specific technical and organisational solutions which – in its view – reduce the risk of breaches. These include multi-factor authentication (MFA), attachment encryption, and the so-called &#8220;3-second rule&#8221;, which involves a brief verification of the recipient and attachments before sending a message.</p>



<p class="wp-block-paragraph">Why does this matter? Because UODO explicitly shows which security measures it currently considers appropriate. This means it is precisely through the prism of such safeguards that the authority may subsequently assess an organisation during an audit or following a personal data breach.</p>



<p class="wp-block-paragraph">Undoubtedly, this is a valuable tip for entrepreneurs. GDPR regulations do not provide an exhaustive list of specific safeguards, limiting themselves to the obligation to implement &#8220;appropriate technical and organisational organisational measures&#8221;. In practice, assessing what is &#8220;appropriate&#8221; remains one of the greatest difficulties for data controllers. The latest bulletin partially fills this gap. It does not create new obligations, but it shows which solutions – from the supervisory authority&#8217;s perspective – correspond to the proper level of electronic mail security today.</p>



<h2 class="wp-block-heading">Significance from the accountability perspective</h2>



<p class="wp-block-paragraph">This is also significant from the perspective of accountability. In the event of a personal data breach, the mere occurrence of an incident does not yet predetermine the controller&#8217;s liability. What is also crucial is whether the organisation was able to demonstrate that it had previously implemented measures adequate to the identified risk. If the President of UODO points out specific solutions today, such as MFA, attachment encryption, or the &#8220;3-second rule&#8221;, it is difficult to assume that they will remain without consequence during an audit or explanatory proceeding.</p>



<h2 class="wp-block-heading">Practical checklist of actions to verify</h2>



<p class="wp-block-paragraph">From the perspective of entrepreneurs, this material should therefore be treated not as yet another reminder of obligations arising from the GDPR, but as a practical checklist of actions that are worth verifying within one&#8217;s own organisation right away. All the more so because all UODO recommendations relate to risks that have for years been among the most common causes of personal data breaches – mailbox takeovers, misaddressed messages, or unauthorised disclosure of data. In practice, these are solutions that not only reduce the likelihood of an incident, but can also constitute a significant argument confirming the exercise of due diligence if a breach occurs despite the implemented safeguards.</p>



<p class="wp-block-paragraph"><em>You can read more on this topic in the article published in Gazeta Prawna. If you wish to discuss how to build a compliance trail that can withstand a UODO audit or check whether your organisation&#8217;s data retention policy covers electronic mail, please feel free to contact us.</em></p><p>The post <a href="https://lbkp.pl/en/uodo-takes-a-closer-look-at-mailboxes-uodo-takes-a-closer-look-at-mailboxes-not-because-you-store-too-many-emails-because-every-additional-message-increases-the-risk/">UODO takes a closer look at mailboxes. UODO takes a closer look at mailboxes. Not because you store too many emails. Because every additional message increases the risk.</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI Act from 2nd August 2026: How to label content created with AI?</title>
		<link>https://lbkp.pl/en/ai-act-from-2nd-august-2026-how-to-label-content-created-with-ai/</link>
		
		<dc:creator><![CDATA[Jacek Cieśliński]]></dc:creator>
		<pubDate>Thu, 20 Aug 2026 08:16:09 +0000</pubDate>
				<category><![CDATA[NewTech Law en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48671</guid>

					<description><![CDATA[<p>AI Act from August 2026: How to label AI content? Discover new rules for businesses, deepfake labelling, texts, and chatbot transparency.</p>
<p>The post <a href="https://lbkp.pl/en/ai-act-from-2nd-august-2026-how-to-label-content-created-with-ai/">AI Act from 2nd August 2026: How to label content created with AI?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<!-- START TABLE OF CONTENTS -->
<nav class="lbkp-toc-box" aria-label="Table of Contents">
  <div class="lbkp-toc-header">
    <span class="lbkp-toc-title">Table of Contents</span>
  </div>
  <ol class="lbkp-toc-list">
    <li><a href="#user-should-know-ai">The user should know they are talking to AI</a></li>
    <li><a href="#labelling-content-ai">Labelling content generated by AI</a></li>
    <li><a href="#what-labelling-look-like">What should the labelling look like?</a></li>
    <li><a href="#texts-prepared-ai">Texts prepared using AI</a></li>
    <li><a href="#responsibility-for-labelling">Responsibility for labelling</a></li>
    <li><a href="#technical-content-labelling">Technical content labelling by AI providers</a></li>
    <li><a href="#content-published-before">Content published before 2nd August 2026</a></li>
    <li><a href="#sanctions">Sanctions</a></li>
    <li><a href="#transparency-ai-usage">Transparency of AI usage</a></li>
  </ol>
</nav>

<style>
  @import url('https://fonts.googleapis.com/css2?family=Roboto:wght@400;500;700&display=swap');

  p {
    margin-bottom: 1.25em !important;
    line-height: 1.7 !important;
  }

  h2 {
    margin-top: 2em !important;
    margin-bottom: 0.8em !important;
  }

  .lbkp-toc-box {
    font-family: 'Roboto', sans-serif;
    background: #f4f6ff;
    border-left: 4px solid #0E20EC;
    padding: 24px 28px;
    margin: 32px 0;
    border-radius: 0 12px 12px 0;
    box-shadow: 0 2px 12px rgba(14, 32, 236, 0.06);
  }

  .lbkp-toc-header {
    margin-bottom: 16px;
  }

  .lbkp-toc-title {
    font-weight: 700;
    font-size: 0.85rem;
    color: #0E20EC;
    text-transform: uppercase;
    letter-spacing: 1.2px;
  }

  .lbkp-toc-list {
    margin: 0;
    padding-left: 20px;
    list-style-type: decimal;
  }

  .lbkp-toc-list li {
    margin-bottom: 10px;
    line-height: 1.6;
    font-size: 0.95rem;
  }

  .lbkp-toc-list li::marker {
    font-weight: 700;
    color: #0E20EC;
  }

  .lbkp-toc-list li:last-child {
    margin-bottom: 0;
  }

  .lbkp-toc-list a {
    color: #1e293b;
    text-decoration: none;
    font-weight: 400;
    display: inline-block;
    transition: all 0.2s cubic-bezier(0.4, 0, 0.2, 1);
  }

  .lbkp-toc-list a:hover {
    color: #0E20EC;
    font-weight: 500;
    transform: translateX(4px);
  }
</style>
<!-- END TABLE OF CONTENTS -->



<p class="wp-block-paragraph">From 2nd August 2026, the AI Act regulations regarding transparency obligations for the use of artificial intelligence come into force. In practice, this means, among other things, the obligation to inform users when they are interacting with an AI system and to label certain content generated or altered with the help of artificial intelligence.</p>



<p class="wp-block-paragraph">These regulations impose obligations on both providers of specific AI systems and entities that use them. In practice, they are particularly relevant for businesses using chatbots and companies utilising generative AI in marketing, advertising, media, e-commerce, or when creating texts, graphics, audio recordings, and video materials.</p>



<p class="wp-block-paragraph">This does not mean that from 2nd August every graphic generated in Midjourney, text prepared with the help of ChatGPT, or photo retouched using AI requires a special label. The scope of obligations depends on how the AI was used and what the final output is.</p>



<h2 class="wp-block-heading">The user should know they are talking to AI</h2>



<p class="wp-block-paragraph">One of the obligations laid down in the AI Act is to ensure that people using AI systems intended for direct interaction with users know that they are communicating with artificial intelligence. This obligation rests on the providers of such systems and applies, amongst others, to customer service chatbots, voicebots, virtual assistants, or AI agents.</p>



<p class="wp-block-paragraph">The information should appear no later than at the first interaction with the user. Therefore, if a customer opens a chat on an online shop&#8217;s website and starts a conversation with a bot, they should know from the outset that there is no human on the other side.</p>



<p class="wp-block-paragraph">Above all, this means verifying whether the implemented system actually transmits the appropriate information to the user and whether it does so at the right moment. Hiding a mention of AI solely within the terms and conditions or the privacy policy may fail to achieve the purpose of these regulations.</p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-full"><img decoding="async" width="2000" height="1196" src="https://lbkp.pl/wp-content/uploads/2026/08/1936.jpg" alt="AI generated" class="wp-image-48669" srcset="https://lbkp.pl/wp-content/uploads/2026/08/1936.jpg 2000w, https://lbkp.pl/wp-content/uploads/2026/08/1936-300x179.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/08/1936-768x459.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/08/1936-1024x612.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/08/1936-1536x919.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/08/1936-370x221.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/08/1936-839x502.jpg 839w, https://lbkp.pl/wp-content/uploads/2026/08/1936-410x245.jpg 410w" sizes="(max-width: 2000px) 100vw, 2000px" /></figure>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Labelling content generated by AI</h2>



<p class="wp-block-paragraph">The mere fact of using artificial intelligence does not automatically trigger an obligation to label the material. A text prepared with the help of ChatGPT must be approached differently from a realistic human image generated for an advertising campaign, and differently again from a photograph where AI has merely improved sharpness or removed noise.</p>



<p class="wp-block-paragraph">In the case of images, audio recordings, and video materials, it is of particular importance whether the created content can be classified as a deepfake. According to the AI Act, this refers to content generated or manipulated by AI in the form of image, sound, or video that resembles existing persons, objects, places, entities, or events and may falsely appear authentic or true. The disclosure obligation applies precisely to such content.</p>



<p class="wp-block-paragraph">A deepfake does not necessarily mean only a video with a politician&#8217;s or celebrity&#8217;s face swapped. In practice, the problem may also arise in much more everyday applications of generative AI: a realistic human image generated by AI, a synthetic voiceover, a generated realistic scenery, or a product photo placed by AI into a new environment.</p>



<p class="wp-block-paragraph">However, not every AI intervention in a material will lead to such a result. Tools utilising artificial intelligence are nowadays part of ordinary photo, graphic, or sound editing software. Quality enhancement, noise reduction, or other technical actions should not automatically be treated the same way as creating a new, realistic situation that did not actually take place in reality.</p>



<h2 class="wp-block-heading">What should the labelling look like?</h2>



<p class="wp-block-paragraph">The information about the use of AI should be clear and noticeable to the recipient no later than upon their first contact with the given content. It is therefore not about hiding information in metadata, terms and conditions, or at the end of a long description that the recipient might never read.</p>



<p class="wp-block-paragraph">In the case of graphics, the label can be placed directly on the image or presented in an equivalent manner within the interface. For video material, it should be visible to the person watching the material, and the method of labelling audio content should allow the recipient to know that the heard material has been generated or modified by AI.</p>



<p class="wp-block-paragraph">The European Commission has prepared a set of EU icons to facilitate content labelling. They distinguish, amongst others, between materials generated entirely by AI and content that existed previously but was subsequently partially modified using artificial intelligence. For instance, a realistic image generated from scratch will fall into the fully generated content category, whereas a real photograph of an empty flat that AI subsequently &#8220;furnished&#8221; is given by the Commission as an example of partially modified content.</p>



<p class="wp-block-paragraph">EU icons for labelling AI content prepared by the European Commission:</p>



<p class="wp-block-paragraph">The use of EU icons is voluntary. One can also apply their own understandable designation, such as &#8220;image generated by AI&#8221; or &#8220;voice generated using AI&#8221;. Choosing one&#8217;s own label does not exempt one from the necessity of ensuring that the information is legible and meets the requirements of the AI Act.</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" width="169" height="112" src="https://lbkp.pl/wp-content/uploads/2026/08/image-14.png" alt="" class="wp-image-48666" style="aspect-ratio:1.5066666666666666;width:113px;height:auto"/></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="169" height="112" src="https://lbkp.pl/wp-content/uploads/2026/08/image-12.png" alt="" class="wp-image-48664" style="aspect-ratio:1.5066666666666666;width:113px;height:auto"/></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="169" height="112" src="https://lbkp.pl/wp-content/uploads/2026/08/image-13.png" alt="" class="wp-image-48665" style="aspect-ratio:1.5066666666666666;width:113px;height:auto"/></figure>



<p class="wp-block-paragraph">Korzystanie z unijnych ikon jest dobrowolne. Można zastosować również własne, zrozumiałe określenie, np. „obraz wygenerowany przez AI” czy „głos wygenerowany przy użyciu AI”. Wybór własnego oznaczenia nie zwalnia z konieczności zadbania o to, aby informacja była czytelna i spełniała wymagania AI Act.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">Texts prepared using AI</h2>



<p class="wp-block-paragraph">The rules regarding texts look different. The AI Act does not introduce a general obligation to label every email, product description, LinkedIn post, or article just because generative AI was used in preparing it.</p>



<p class="wp-block-paragraph">The obligation applies to texts generated or manipulated by AI and published with the aim of informing the public on matters of public interest. In practice, these might be, for example, materials concerning politics, security, public health, the environment, or other matters significant from the point of view of public debate. Ordinary sales or marketing texts will not, as a rule, automatically fall into this category.</p>



<p class="wp-block-paragraph">At the same time, the AI Act provides an important exception. Labelling is not required if the AI-generated text has undergone human review or editorial control, and editorial responsibility for the publication is assumed by a natural or legal person.</p>



<p class="wp-block-paragraph">However, such control should not be reduced solely to correcting typos and commas. If AI prepares material concerning matters of public interest, human verification should be of a genuine nature, meaning it should encompass content assessment, fact-checking, and the final decision to publish.</p>



<h2 class="wp-block-heading">Responsibility for labelling</h2>



<p class="wp-block-paragraph">The AI Act distinguishes between the obligations of AI system providers and the entities that use those systems. Providers are responsible, amongst others, for certain technical mechanisms enabling the detection of content generated or modified by AI, whilst deploying entities face obligations such as disclosing deepfakes and specific texts concerning matters of public interest.</p>



<p class="wp-block-paragraph">In practice, cooperation with advertising agencies, production studios, or freelancers requires special attention. If materials are prepared by an external entity, it is wise to establish in advance whether and to what extent they may use AI, as well as how content requiring labelling will be identified.</p>



<h2 class="wp-block-heading">Technical content labelling by AI providers</h2>



<p class="wp-block-paragraph">As for the obligations of AI system providers, these primarily concern the technical labelling of content generated by those systems. On the providers&#8217; side, the obligation is therefore primarily of a technical nature and does not have to be visible to the recipient. Article 50(2) of the AI Act requires systems generating synthetic text, image, audio, or video to mark the outputs in a machine-readable format, enabling the detection that they have been generated or manipulated by AI. The regulations do not mandate a single technology: these could be, for example, digital watermarks, provenance metadata, cryptographic solutions, or fingerprinting.</p>



<p class="wp-block-paragraph">For systems placed on the market before 2nd August 2026, however, the AI Act provides a transitional period; their providers have until 2nd December 2026 to adapt to this obligation. For systems placed on the market from 2nd August 2026, this obligation applies from the moment of their introduction.</p>



<p class="wp-block-paragraph">AI system providers are already beginning to implement such solutions in practice. An example is Anthropic, which announced the use of two types of markings in Claude: user-invisible watermarks embedded in the generated text and digitally signed provenance metadata for supported graphic files. In the case of text, this is not about adding invisible watermarks or hidden information to a ready-made response. The mechanism operates already at the generation stage. The way the model chooses subsequent words creates a specific pattern that the user is unable to notice during normal reading, but which can later be detected using an appropriate tool, which Anthropic has announced it is already working on. The tool is intended to allow verification of whether the pattern characteristic of Claude is present in the analysed text, and thus assessment of whether the content was processed by the model. However, the result of such an analysis itself will not constitute unequivocal proof of the text&#8217;s origin.</p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="612" src="https://lbkp.pl/wp-content/uploads/2026/08/1936-1024x612.jpg" alt="" class="wp-image-48669" srcset="https://lbkp.pl/wp-content/uploads/2026/08/1936-1024x612.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/08/1936-300x179.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/08/1936-768x459.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/08/1936-1536x919.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/08/1936-370x221.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/08/1936-839x502.jpg 839w, https://lbkp.pl/wp-content/uploads/2026/08/1936-410x245.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/08/1936.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"></p>



<h2 class="wp-block-heading">Content published before 2nd August 2026</h2>



<p class="wp-block-paragraph">Companies do not have to revisit all materials generated and made available before 2nd August 2026 solely to label them in accordance with the new rules. The Commission has confirmed that the obligation is not retroactive in this respect, although it encourages voluntary labelling of earlier content where possible.</p>



<p class="wp-block-paragraph">It is worth approaching materials prepared earlier but still used after the new regulations come into force with caution, however, especially in actively run campaigns. In such cases, the manner of applying the rules may require an assessment of the specific scenario.</p>



<h2 class="wp-block-heading"><strong>Sanctions</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Infringing transparency obligations can incur administrative fines reaching up to EUR 15 million or 3% of the company&#8217;s total worldwide annual turnover for the preceding financial year.</p>



<p class="wp-block-paragraph">However, a fine under the AI Act is not the only risk associated with the improper use of AI-generated content. Unlabelled material may also cause reputational issues or lead to allegations related to misleading communication.</p>



<p class="wp-block-paragraph">On top of this, entirely different areas of law may apply. Using a specific person&#8217;s likeness may require analysis from the perspective of personality rights, processing personal data from the GDPR perspective, and using other people&#8217;s materials when creating content may raise copyright questions. Simply adding an &#8220;AI Generated&#8221; label does not automatically mean that the way the material is used complies with the law.</p>



<h2 class="wp-block-heading">Transparency of AI usage</h2>



<p class="wp-block-paragraph">The AI Act does not prohibit the use of generative artificial intelligence in marketing, customer service, or content creation. The new regulations are primarily intended to ensure that, in specific situations, the recipient knows they are in contact with artificial intelligence or that the material presented to them has been generated or modified with its help.</p>



<p class="wp-block-paragraph">For enterprises, this means above all the need to organise how they use AI: determining where synthetic content is created, who is responsible for its assessment, and how information obligations will be fulfilled in practice.</p>



<h2 class="wp-block-heading has-bg-color-color has-text-hover-2-background-color has-text-color has-background has-link-color wp-elements-1">Author:</h2>


<div 		class="sc_team sc_team_list"><div class="sc_team_columns_wrap sc_item_columns sc_item_posts_container trx_addons_columns_wrap columns_padding_bottom columns_in_single_row"><div class="trx_addons_column-1_2"><div data-post-id="45704" class="sc_team_item sc_item_container post_container no_links post-45704 cpt_team type-cpt_team status-publish has-post-thumbnail hentry cpt_team_group-associates-en">
	<div class="post_featured sc_team_item_thumb trx_addons_hover trx_addons_hover_style_info_anim"><img loading="lazy" decoding="async" width="570" height="696" src="https://lbkp.pl/wp-content/uploads/2026/02/Frame-92-570x696.jpg" class="attachment-wabi-sabi-thumb-rectangle size-wabi-sabi-thumb-rectangle wp-post-image" alt="Wojciech Kulig" /><a class="post_link sc_team_item_link" href="https://lbkp.pl/en/team/wojciech-kulig-en/"></a><div class="trx_addons_hover_mask"></div></div>	<div class="sc_team_item_info">
		<div class="sc_team_item_header">
			<h4 class="sc_team_item_title entry-title"><a href="https://lbkp.pl/en/team/wojciech-kulig-en/">Wojciech Kulig</a></h4>
			<div class="sc_team_item_subtitle">Junior associate</div>							<div class="sc_team_item_content">
					<p>He supports clients in matters related to new technology law, in particular in the areas of personal data protection, intellectual property and issues related to artificial intelligence.</p>
				</div>
					</div>
	</div>
</div>
</div></div></div><p>The post <a href="https://lbkp.pl/en/ai-act-from-2nd-august-2026-how-to-label-content-created-with-ai/">AI Act from 2nd August 2026: How to label content created with AI?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>July Round-up at LBKP: Employment Law, the AI Act, NIS2 and GameDev</title>
		<link>https://lbkp.pl/en/july-round-up-at-lbkp-employment-law-the-ai-act-nis2-and-gamedev/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 17 Aug 2026 12:42:53 +0000</pubDate>
				<category><![CDATA[Culture Book en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48661</guid>

					<description><![CDATA[<p>July at LBKP was dominated by employment law. There was no shortage of significant legislative&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/july-round-up-at-lbkp-employment-law-the-ai-act-nis2-and-gamedev/">July Round-up at LBKP: Employment Law, the AI Act, NIS2 and GameDev</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph"><strong>July at LBKP was dominated by employment law.</strong> There was no shortage of significant legislative changes, expert commentary, and practical analyses. The spotlight was also on AML-related topics, as well as NIS2 and the AI Act, which consistently remain among the most crucial areas for business.</p>



<p class="wp-block-paragraph">In this issue, we have also gathered the most interesting materials from the past month – from expert analyses and event reports to selected publications as part of the TechnoLegals programme. We hope this bulletin will be a convenient way for you to quickly catch up on July&#8217;s most important topics.</p>



<p class="wp-block-paragraph">Our bulletin summarises July, but since you are reading it in August on LinkedIn, we couldn&#8217;t skip the AI Act. Therefore, at the end, we are leaving a brief reminder of the most important rules regarding the publication of content using artificial intelligence.</p>



<h3 class="wp-block-heading">The AI Act and LinkedIn – who needs to label AI-generated content?</h3>



<p class="wp-block-paragraph">Here is the translation of the newsletter into British English, with formatting added to enhance readability:</p>



<p class="wp-block-paragraph"><strong>July at LBKP was dominated by employment law.</strong> There was no shortage of significant legislative changes, expert commentary, and practical analyses. The spotlight was also on AML-related topics, as well as NIS2 and the AI Act, which consistently remain among the most crucial areas for business.</p>



<p class="wp-block-paragraph">In this issue, we have also gathered the most interesting materials from the past month – from expert analyses and event reports to selected publications as part of the TechnoLegals programme. We hope this bulletin will be a convenient way for you to quickly catch up on July&#8217;s most important topics.</p>



<p class="wp-block-paragraph">Our bulletin summarises July, but since you are reading it in August on LinkedIn, we couldn&#8217;t skip the AI Act. Therefore, at the end, we are leaving a brief reminder of the most important rules regarding the publication of content using artificial intelligence.</p>



<h3 class="wp-block-heading">The AI Act and LinkedIn – who needs to label AI-generated content?</h3>



<p class="wp-block-paragraph">Since 2 August, new AI Act regulations regarding transparency in the use of artificial intelligence have been in force. A lot of questions and misunderstandings have arisen around the new regulations, which is why we have prepared a practical guide showing what actually changes for companies, experts, and participants in employee advocacy programmes.</p>



<ol start="1" class="wp-block-list">
<li><strong>It is the publisher who is responsible for labelling the content</strong> The obligation of transparency rests with the person or organisation publishing the material – not with LinkedIn or the AI tool you are using.</li>



<li><strong>Not every text written with the help of AI needs to be labelled</strong> If the text has been verified, edited, and consciously published by a specific person, in most cases, it will not require a label. It may be different in the case of content concerning matters of public interest.</li>



<li><strong>Particular attention should be paid to graphics and video</strong> Realistic images, video recordings, or audio materials generated by AI may be subject to the labelling obligation. In the case of clearly fictional illustrations, the regulations provide for exceptions.</li>



<li><strong>Employee advocacy is also a professional activity</strong> Publishing content as part of an ambassador programme – even on a private LinkedIn profile – can be considered a professional activity. It is the nature of the publication that matters, not the type of account.</li>



<li><strong>It is worth establishing clear rules for using AI</strong> The new regulations do not prohibit the use of artificial intelligence in communication. However, they &#8220;encourage&#8221; greater transparency, so companies operating on LinkedIn should develop consistent rules for using AI when creating content.</li>
</ol>



<p class="wp-block-paragraph">This is a topic that will be relevant not only for marketing departments but also for HR, communications, and anyone building an expert brand on social media.</p>



<h3 class="wp-block-heading">Summer Academy of GDPR Leaders: Practical Aspects of Audits and Implementations</h3>



<p class="wp-block-paragraph">Grzegorz Lesniewski has joined the panel of experts of the Summer Academy of GDPR Leaders organised by the Personal Data Protection Office. During a lecture dedicated to the practical aspects of GDPR audits, he will share his experience gained while carrying out compliance implementations and projects in organisations.</p>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7483089962180141056"><img loading="lazy" decoding="async" width="1024" height="327" src="https://lbkp.pl/wp-content/uploads/2026/08/image-1024x327.png" alt="" class="wp-image-48647" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-1024x327.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-300x96.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-768x245.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-370x118.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-840x268.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-410x131.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image.png 1298w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">EmpCo: Will products prepared before 27 September 2026 need to be withdrawn from the market?</h3>



<p class="wp-block-paragraph">The Consumer Protection Cooperation (CPC) network has published a practical position regarding the so-called <em>old stock situations</em>, i.e., products, packaging, and marketing communication prepared before the EmpCo directive becomes applicable. The document indicates how authorities may approach the transitional period and the enforcement of new obligations.</p>



<p class="wp-block-paragraph"><strong>Key takeaways for businesses:</strong></p>



<ul class="wp-block-list">
<li>The mere fact of having stock does not exempt you from the obligation to adapt communication to the new requirements. The priority should be updating online content and gradually introducing changes to packaging and marketing materials.</li>



<li>The authorities announce a pragmatic approach to the transitional period, taking into account, among other things, the scale of stocks and the realistic capabilities of businesses. However, it will be crucial to demonstrate that the organisation is actively preparing to ensure compliance with the regulations.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7480581272076148736"><img loading="lazy" decoding="async" width="1024" height="331" src="https://lbkp.pl/wp-content/uploads/2026/08/image-1-1024x331.png" alt="" class="wp-image-48648" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-1-1024x331.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-768x248.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-1290x418.png 1290w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-840x272.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-1-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-1.png 1292w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">A well-negotiated settlement does not always mean the best financial outcome.</h3>



<h3 class="wp-block-heading">Dispute resolution strategy</h3>



<p class="wp-block-paragraph">The Supreme Court has confirmed that an out-of-court settlement does not always constitute a basis for the refund of the entire statement of claim fee. In practice, this means that when planning to end a dispute, not only the content of the agreement matters, but also the manner and timing of its conclusion.</p>



<p class="wp-block-paragraph"><strong>What is worth paying attention to?</strong></p>



<ul class="wp-block-list">
<li>The choice between an out-of-court settlement, a court settlement, or mediation can have a significant impact on the settlement of the proceedings&#8217; costs.</li>



<li>The dispute resolution strategy should take into account not only the business interests of the parties but also the procedural and financial consequences of the chosen solution.</li>
</ul>



<h3 class="wp-block-heading">Terminating Cooperation with an Employee</h3>



<h3 class="wp-block-heading">The date of posting the notice is not the date of its submission.</h3>



<p class="wp-block-paragraph">Delivering a termination notice by post or courier might seem like a simple solution, but in practice, the moment the statement is submitted depends on its effective delivery to the employee. It is this very stage that often becomes a source of costly mistakes and disputes.</p>



<p class="wp-block-paragraph"><strong>What should you remember?</strong></p>



<ul class="wp-block-list">
<li>A statement on the termination of an agreement produces legal effects only when the employee has had a real opportunity to familiarise themselves with its content – the mere posting of the parcel is not sufficient.</li>



<li>Problems with delivery, leaving a missed delivery card (aviso), or a lost parcel can affect the effectiveness of the agreement&#8217;s termination, so it is worth considering more secure forms of delivery, including electronic solutions.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7483166436182585344"><img loading="lazy" decoding="async" width="1024" height="336" src="https://lbkp.pl/wp-content/uploads/2026/08/image-2-1024x336.png" alt="" class="wp-image-48649" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-2-1024x336.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-2-300x98.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-2-768x252.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-2-370x121.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-2-840x276.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-2-410x135.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-2.png 1286w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h2 class="wp-block-heading">New Employer Obligations: Changes in Mobbing Regulations (November 2026)</h2>



<p class="wp-block-paragraph">The amendment will come into force 3 months after its publication (i.e. on 5.11.2026). From that moment, we have its new definition, and employers will bear the brunt of the changed obligations.</p>



<p class="wp-block-paragraph">Including the most important one &#8211; the obligation to <strong>SYSTEMATICALLY</strong> counteract violations of the principle of equal treatment in employment. A longer deadline is envisaged for adjusting or introducing internal company regulations on counteracting undesirable behaviour &#8211; 6 months from the date the act comes into force (i.e. by 5.05.2027).</p>



<p class="wp-block-paragraph"><strong>Why is it worth preparing now?</strong></p>



<ul class="wp-block-list">
<li>The amendment changes not only the definitions but also increases the importance of preventive measures. Employers should review current procedures, training, and how they respond to reports.</li>



<li>The changes should be analysed in conjunction with the new powers of the National Labour Inspectorate (PIP), as their practical application may significantly affect how risk is managed in the HR area.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7478811526758408193"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/08/image-10-1024x332.png" alt="" class="wp-image-48657" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-10-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-1290x420.png 1290w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-840x273.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-10-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-10.png 1294w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">A &#8220;disciplinary termination&#8221; submitted by an employee? The employer cannot reject it.</h3>



<p class="wp-block-paragraph">The termination of an employment contract by an employee under Article 55 of the Labour Code takes effect upon the effective submission of the statement. This means that the employer cannot refuse to terminate the employment relationship, even if they consider the employee&#8217;s decision to be unjustified.</p>



<p class="wp-block-paragraph"><strong>What can the employer do?</strong></p>



<ul class="wp-block-list">
<li>Despite the obligation to issue an employment certificate, the employer may question the legitimacy of the contract&#8217;s termination, refuse to pay compensation, or – in specific cases – claim compensation from the employee for the unjustified termination of the employment relationship.</li>



<li>However, the employer&#8217;s claims are limited. The regulations provide for the possibility of seeking compensation, but do not provide grounds to demand the employee&#8217;s reinstatement to work.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/posts/pawel-kempa-dyminski_wakacje-kojarz%C4%85-si%C4%99-z-okresem-nieco-leniwym-share-7491795227851292672-A-rI"><img loading="lazy" decoding="async" width="1024" height="328" src="https://lbkp.pl/wp-content/uploads/2026/08/image-3-1024x328.png" alt="" class="wp-image-48650" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-3-1024x328.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-300x96.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-768x246.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-370x118.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-1290x414.png 1290w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-840x269.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-3-410x131.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-3.png 1294w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">&#8220;The employee is on sick leave (L4), so there is nothing we can do.&#8221;</h3>



<p class="wp-block-paragraph">This is one of the most frequently repeated myths in employment law. Natalia Wojciechowska-Chałupińska, in a commentary for <em>Gazeta Prawna</em>, explains when the protection of an employee on sick leave is not absolute and what exceptions the regulations provide for.</p>



<p class="wp-block-paragraph"><strong>What does this mean for employers?</strong></p>



<ul class="wp-block-list">
<li>Sick leave does not preclude the termination of an agreement in every situation – the regulations provide for exceptions, e.g. in the event of long-term incapacity for work or a severe breach of employee duties.</li>



<li>Every decision requires an individual assessment of the factual state and the correct application of the regulations, as mistakes at this stage often lead to court disputes.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7478756649344602112/?actorCompanyId=18729709"><img loading="lazy" decoding="async" width="1024" height="330" src="https://lbkp.pl/wp-content/uploads/2026/08/image-5-1024x330.png" alt="" class="wp-image-48652" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-5-1024x330.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-5-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-5-768x247.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-5-370x119.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-5-840x271.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-5-410x132.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-5.png 1298w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">Reclassification of B2B Contracts: What to pay attention to during an audit?</h3>



<p class="wp-block-paragraph">During an inspection, it is not only the content of the contract that matters, but above all, the way it is performed.</p>



<p class="wp-block-paragraph">An audit of B2B contracts should not be limited to analysing contractual provisions. Controlling bodies also verify the practice of cooperation – procedures, rules applicable in the organisation, and the actual way duties are performed. It is on this basis that they assess whether the relationship is indeed of a B2B nature.</p>



<p class="wp-block-paragraph"><strong>What is worth paying attention to?</strong></p>



<ul class="wp-block-list">
<li>An effective audit covers not only contracts but also processes, internal documentation, and the daily practice of cooperation. These often determine the risk of reclassifying the contract into an employment relationship.</li>
</ul>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph"><em>Free webinars concerning audits of B2B contracts and the practical aspects of preparing an organisation for an inspection are also available on the LBKP website.</em></p>
</blockquote>



<figure class="wp-block-image size-large"><a href="https://lbkp.pl/nowe-uprawnienia-pip/"><img loading="lazy" decoding="async" width="1024" height="287" src="https://lbkp.pl/wp-content/uploads/2026/08/image-6-1024x287.png" alt="" class="wp-image-48653" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-6-1024x287.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-6-300x84.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-6-768x215.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-6-370x104.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-6-840x236.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-6-410x115.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-6.png 1284w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">DORA: new EBA guidelines for the financial sector. The EBA expands its approach to supplier risk management.</h3>



<p class="wp-block-paragraph">Financial institutions that have completed the implementation of DORA should not treat it as a closed project. The European Banking Authority (EBA) has just launched consultations on new guidelines concerning the management of risks related to external suppliers. This is another step showing the direction in which supervision will develop.</p>



<p class="wp-block-paragraph"><strong>The most important conclusion?</strong> Supplier risk management is ceasing to be the exclusive domain of IT and cybersecurity departments.</p>



<p class="wp-block-paragraph">The new guidelines indicate that financial institutions should pay even more attention to:</p>



<ul class="wp-block-list">
<li><strong>the entire lifecycle of cooperation with a supplier</strong> – from selection and risk assessment, through ongoing monitoring, to the termination of cooperation,</li>



<li><strong>managing concentration risk</strong>, i.e., identifying situations where too many critical services rely on a single supplier or the same group of suppliers,</li>



<li><strong>governance and business responsibility</strong> – supplier risk management is to be a process involving not only IT, but also compliance, risk management, procurement, and the management board.</li>
</ul>



<p class="wp-block-paragraph">Although the guidelines are still at the consultation stage, they already show the direction of European regulators&#8217; expectations. For banks and other financial institutions, this means it is worth taking another look at the supplier management model, the division of responsibilities, and the processes for monitoring services provided by external entities.</p>



<p class="wp-block-paragraph">DORA is increasingly clearly demonstrating that digital operational resilience does not end with the security of IT systems. It encompasses the entire ecosystem of suppliers upon whom the continuity of the organisation&#8217;s operations depends.</p>



<h3 class="wp-block-heading">AML is no longer the domain of banks. It is increasingly becoming the responsibility of management boards.</h3>



<p class="wp-block-paragraph">AML (Anti-Money Laundering) &#8211; New EU regulations and the expansion of the list of obliged institutions mean that AML is covering further sectors of the economy. At the same time, expectations towards organisations regarding effective risk management and supervision of the compliance system are growing.</p>



<p class="wp-block-paragraph"><strong>Why is this important?</strong> AML is becoming an element of corporate governance. The obligations of management boards and their responsibility for ensuring an effective anti-money laundering system are of growing importance.</p>



<p class="wp-block-paragraph">Merely having procedures is not enough. Organisations should regularly update their risk assessments, adapt their AML system to their operations, and demonstrate that the solutions applied work in practice.</p>



<figure class="wp-block-image size-large"><a href="https://lbkp.pl/aml-wyplywa-na-szersze-wody-czy-wiesz-kto-dzis-za-to-odpowiada/"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/08/image-7-1024x332.png" alt="" class="wp-image-48654" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-7-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-7-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-7-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-7-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-7-840x272.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-7-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-7.png 1284w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">NIS2: the first deadlines are already running. Does your organisation know that it is covered by the new obligations?</h3>



<p class="wp-block-paragraph">The new regulations cover a much broader catalogue of organisations than previous cybersecurity regulations. The sectors covered by the act include, among others, energy, transport, banking and financial market infrastructure, healthcare, digital infrastructure, telecommunications, ICT service management, postal services, waste management, chemicals and food production, as well as selected types of manufacturing and digital services.</p>



<p class="wp-block-paragraph">In practice, this means that the regulations may apply to, among others, banks, hospitals, energy companies, cloud service providers, data centres, managed service providers (MSPs), managed security service providers (MSSPs), telecommunications undertakings, trust service providers, marketplace platforms, internet search engines, postal and courier companies, electronics and medical device manufacturers, or companies from the chemical, food, and waste management sectors.</p>



<h3 class="wp-block-heading">Podmiot kluczowy czy ważny?</h3>



<p class="wp-block-paragraph"><strong>An essential or important entity?</strong> <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <em>The industry itself does not yet determine the organisation&#8217;s status.</em></p>



<p class="wp-block-paragraph">When determining whether a given organisation is an essential entity, an important entity, or is not subject to the act at all, one must primarily analyse:</p>



<ul class="wp-block-list">
<li>the actual scope of operations and services provided,</li>



<li>the sector and type of entity indicated in Annex 1 or 2 to the act,</li>



<li>the size of the enterprise, taking into account partner and linked enterprises,</li>



<li>specific rules arising from Article 5 of the act.</li>
</ul>



<p class="wp-block-paragraph">In simplified terms: entities operating in the sectors indicated in Annex 1 can be essential or important entities depending on, among other things, their size. Entities from Annex 2 meeting the appropriate size criteria are generally important entities. However, the act provides for exceptions and special rules for, among others, electronic communications undertakings, DNS service providers, trust service providers, or managed security service providers.</p>



<p class="wp-block-paragraph">Therefore, a cloud provider, data centre, or company providing IT services does not automatically become an essential or important entity solely due to the type of its operations.</p>



<p class="wp-block-paragraph">This is important because the new regulations are not based on an individual notification from the authority. It is the entrepreneur themselves who should analyse their operations and assess whether they meet the criteria for being deemed an essential or important entity. If so, specific obligations and deadlines arise. One of the closest is <strong>3 October 2026</strong>, by which many entities will have to register in the KSC (National Cybersecurity System) Register. Another significant deadline is <strong>3 April 2027</strong>, when the period for implementing the obligations arising from the act and starting to use the S46 system expires.</p>



<p class="wp-block-paragraph">In practice, however, preparation for NIS2 does not come down to registration. Organisations should verify, among other things, the way cybersecurity risk is managed, incident reporting procedures, business continuity plans, supply chain security, and the division of responsibilities between the management board, IT, compliance, and business. It is these areas that will be of crucial importance when assessing compliance with the new requirements.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p class="wp-block-paragraph">If your organisation has not yet checked whether it falls within the scope of NIS2, it is worth doing so as soon as possible. In many cases, the greatest risk will not be the lack of a single procedure, but starting the entire adaptation process too late.</p>
</blockquote>



<h3 class="wp-block-heading">Coldplay in Fortnite. When music becomes a gameplay element</h3>



<p class="wp-block-paragraph">On the occasion of the premiere of the <em>Moon Music</em> album, the band Coldplay appeared in the playable iHeartLand experience in Fortnite. This is an interesting example showing that the use of music in games increasingly goes beyond the classic soundtrack and becomes an integral element of gameplay mechanics. From a legal perspective, this means much more complex issues related to the licensing of copyright.</p>



<p class="wp-block-paragraph"><strong>Why is this important?</strong></p>



<ul class="wp-block-list">
<li>When using music in games, it is necessary to properly secure the rights to the compositions, recordings, and artistic performances, as well as define the rules for using the works in trailers, live broadcasts, or materials published on social media.</li>



<li>The more tightly music is integrated with the game mechanics – e.g. triggered by the player&#8217;s actions, looped, or constituting a gameplay element – the more important it becomes to precisely define the scope of the licence and ensure compliance with the requirements of distribution platforms.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7488876318152060928"><img loading="lazy" decoding="async" width="1024" height="331" src="https://lbkp.pl/wp-content/uploads/2026/08/image-8-1024x331.png" alt="" class="wp-image-48655" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-8-1024x331.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-768x248.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-1290x418.png 1290w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-840x271.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-8-410x132.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-8.png 1294w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">A publishing agreement is not a formality. It is one of the most important stages of a game&#8217;s commercialisation.</h3>



<p class="wp-block-paragraph">For many game development studios, negotiations with a publisher are their first experience of this kind. Meanwhile, publishers conclude similar agreements regularly and know perfectly well which provisions are of the greatest importance for the project&#8217;s future. As a result, it is during the negotiation stage that decisions are often made that affect how the game is commercialised and the scope of rights remaining with the studio.</p>



<p class="wp-block-paragraph"><strong>Why is this important?</strong></p>



<ul class="wp-block-list">
<li>Well-prepared negotiations allow for a conscious determination of the rules regarding intellectual property rights, revenue sharing, the parties&#8217; obligations, or the possibilities for further project development. It is these provisions that often have a greater impact on the studio&#8217;s future success than the mere signing of the agreement.</li>



<li>In practice, it is worth remembering that experience in game development does not always go hand in hand with experience in negotiating publishing contracts. Proper preparation for talks allows the studio&#8217;s interests to be better protected and avoids the consequences resulting from unknowingly accepted clauses.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7487530600946515969"><img loading="lazy" decoding="async" width="1024" height="336" src="https://lbkp.pl/wp-content/uploads/2026/08/image-9-1024x336.png" alt="" class="wp-image-48656" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-9-1024x336.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-9-300x98.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-9-768x252.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-9-370x121.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-9-840x276.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-9-410x135.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-9.png 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">Does &#8220;buying a game&#8221; mean owning it?</h3>



<p class="wp-block-paragraph">The <em>Stop Killing Games</em> initiative has sparked a broad discussion about players&#8217; rights and publishers&#8217; obligations after ending support for games. Although the European Commission&#8217;s response does not mean imposing an obligation on publishers to maintain online infrastructure for an unlimited time, the debate has once again drawn attention to the issue of transparency towards consumers using digital products.</p>



<p class="wp-block-paragraph"><strong>A question worth asking yourself:</strong> Players should know already at the purchase stage whether they are buying a game or merely a licence to use it, how long the product will be supported, and what will happen to it after the servers are shut down. Clear rules regarding the access model and the publisher&#8217;s obligations can reduce the risk of misunderstandings and increase trust in the market.</p>



<p class="wp-block-paragraph">The discussion around the <em>Stop Killing Games</em> initiative will probably not end with the European Commission&#8217;s response. The planned <strong>Digital Fairness Act</strong> may become the next step towards strengthening information obligations towards consumers and setting new standards for the digital games industry.</p>



<figure class="wp-block-image size-large"><a href="https://pl.linkedin.com/feed/update/urn:li:activity:7482763386770886656"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/08/image-11-1024x332.png" alt="" class="wp-image-48658" srcset="https://lbkp.pl/wp-content/uploads/2026/08/image-11-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-1290x420.png 1290w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-840x272.png 840w, https://lbkp.pl/wp-content/uploads/2026/08/image-11-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/08/image-11.png 1296w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">LBKP&#8217;s Plans for August: HR, Employment Law, and Webinars</h3>



<p class="wp-block-paragraph">August promises to be equally intense. In the coming weeks, we will be sharing further materials for entrepreneurs, HR departments, and the new technologies industry, as well as working on new initiatives that will respond even better to your needs.</p>



<p class="wp-block-paragraph"><strong>It is worth following our profiles if you are interested in:</strong></p>



<p class="wp-block-paragraph">→ further analyses and commentary on employment law, AI, cybersecurity, AML, and GameDev,</p>



<p class="wp-block-paragraph">→ new publications dedicated to legislative changes and their practical impact on business,</p>



<p class="wp-block-paragraph">→ a new bulletin dedicated to HR specialists and employers, in which we will focus on the practical aspects of employment law, team management, and the most important challenges facing HR departments,</p>



<p class="wp-block-paragraph">→ the return of our webinars as early as September – we are preparing further online meetings dedicated to the most current issues in the areas of law, tax, and business.</p>



<p class="wp-block-paragraph">Thank you for reading the July issue of LBKP Inside. See you in the next edition!</p><p>The post <a href="https://lbkp.pl/en/july-round-up-at-lbkp-employment-law-the-ai-act-nis2-and-gamedev/">July Round-up at LBKP: Employment Law, the AI Act, NIS2 and GameDev</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AML is &#8220;sailing&#8221; into broader waters. Do you know who is responsible for it today?</title>
		<link>https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 13:16:05 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48564</guid>

					<description><![CDATA[<p>Table of Contents For years, anti-money laundering (AML) was primarily associated with banks, financial institutions,&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/">AML is “sailing” into broader waters. Do you know who is responsible for it today?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Table of Contents</p>



<ol class="wp-block-list">
<li><a href="#the-bank-is-no-longer-the-sole-gatekeeper">The bank is no longer the sole gatekeeper</a></li>



<li><a href="#a-procedure-is-no-longer-a-shelf-ware-alibi">A procedure is no longer a &#8220;shelf-ware alibi&#8221;</a></li>



<li><a href="#should-you-have-known">&#8220;Should you have known?&#8221;</a></li>



<li><a href="#a-companys-problem-can-quickly-become-a-board-members-problem">A company&#8217;s problem can quickly become a board member&#8217;s problem</a></li>



<li><a href="#aml-is-becoming-an-element-of-enterprise-management">AML is becoming an element of enterprise management</a></li>



<li><a href="#the-new-boundary-of-liability">The new boundary of liability</a></li>



<li><a href="#aml-is-entering-new-sectors-today">AML is entering new sectors today. But above all, it is entering boardrooms.</a></li>
</ol>



<p class="wp-block-paragraph">For years, anti-money laundering (AML) was primarily associated with banks, financial institutions, beneficial owner forms, and a million questions about where the client got their money from. It was a world of procedures, transaction alerts, and specialists locked away in compliance departments. That world is now definitively coming to an end.</p>



<p class="wp-block-paragraph">AML is increasingly ceasing to be the exclusive domain of the financial sector. Meanwhile, its core requirements are making their way into law firms, tech companies, accounting offices, estate agencies, crypto market operators, luxury goods traders, and even professional sports. The EU AML package further expands the catalogue of obliged entities to include, among others, a significant portion of the crypto sector, luxury goods dealers, as well as professional football clubs and agents.</p>



<p class="wp-block-paragraph">At the same time, the European Anti-Money Laundering Authority (AMLA) has been established to strengthen and harmonise supervision across the entire system. However, this is not just about adding more industries to the legislation. Much more important is the shift in how liability is perceived.</p>



<h2 class="wp-block-heading">The bank is no longer the sole gatekeeper</h2>



<p class="wp-block-paragraph">The AML system is based on the premise that it is not only the state that is supposed to &#8220;hunt down&#8221; criminals. Private entities standing between the client and the transaction are also expected to assist.</p>



<p class="wp-block-paragraph">A bank sees the flow of money. An accountant knows the settlement structure. An estate agent sees who is buying the apartment. An advisor helps structure a transaction. A law firm may be involved in setting up a company, acquiring a business, or managing a client&#8217;s assets. In the eyes of the European legislator, each of these entities is a gatekeeper to the legitimate economy.</p>



<p class="wp-block-paragraph">In Poland, advocates, attorneys-at-law, foreign lawyers, and tax advisors are already obliged entities when they provide assistance concerning, inter alia, the buying and selling of real estate or enterprises, managing assets, opening accounts, making contributions, and creating or managing companies. This does not mean that every piece of legal advice is subject to AML. It does mean, however, that a law firm participating in certain transactions can no longer assume that the issue of the origin of funds is solely the bank&#8217;s problem.</p>



<p class="wp-block-paragraph">The same applies to entrepreneurs. Not every entrepreneur is directly an obliged entity. However, almost anyone can encounter AML as a bank client, a participant in a transaction, an entity disclosing its ultimate beneficial owner, or a contractor whose ownership structure, funding source, or payment routing starts to raise questions.</p>



<p class="wp-block-paragraph">AML is therefore spilling beyond the formal statutory catalogue. It enters ordinary business operations through the back door, via banks, contractors, audits, financing, and corporate group requirements. The only limitation here is the &#8220;processing capacity&#8221; of the supervisory authorities.</p>



<h2 class="wp-block-heading">A procedure is no longer a &#8220;shelf-ware alibi&#8221;</h2>



<p class="wp-block-paragraph">Even a few years ago, many organisations treated compliance quite simply: we write a voluminous procedure that is essentially unreadable, conduct some generic training, collect signatures, and place the document in a suitably thick binder or a beautifully named folder on a shared drive.</p>



<p class="wp-block-paragraph">The binder had one fundamental advantage: it looked professional, and the drive was backed up.</p>



<p class="wp-block-paragraph">The problem is that regulators are increasingly less likely to ask merely whether a procedure existed. They ask whether it was tailored to the actual business model, whether it identified specific risks, whether it was updated, and whether anyone checked if it was working.</p>



<p class="wp-block-paragraph">In the current approach, risk assessment cannot be reduced to labelling a client as &#8220;low&#8221;, &#8220;normal&#8221;, or &#8220;high&#8221;. The risk category must influence the scope and intensity of the actions actually taken. A change in product, distribution channel, geographical area, client structure, or political situation may require an immediate update of the assessment. The authority also expects the documentation to allow for the verification of the effectiveness of the measures applied, and for the risk assessment to be approved by responsible persons at the management level.</p>



<p class="wp-block-paragraph">In other words, a procedure sitting on a server proves at most that someone knew how to write or outsource writing. It does not prove that the organisation knows how to manage risk.</p>



<h2 class="wp-block-heading">&#8220;Should you have known?&#8221;</h2>



<p class="wp-block-paragraph">This is where the most dangerous shift occurs.</p>



<p class="wp-block-paragraph">Liability is increasingly not based solely on the question of whether someone actually knew about the suspicious nature of a transaction. The question of whether you <em>should have</em> noticed it under a properly organised system is becoming ever more crucial.</p>



<p class="wp-block-paragraph">Did the client&#8217;s profile match the nature of the transaction? Was the source of funds credible? Did the ownership structure make commercial sense? Was the sudden change in payment routing explained? Did the intermediary have a genuine business justification? Did anyone connect several seemingly neutral pieces of information?</p>



<p class="wp-block-paragraph">This is no longer a classic document check. It is an obligation to draw conclusions.</p>



<p class="wp-block-paragraph">The regulator does not expect clairvoyance. However, they do expect the organisation to know its own business well enough to spot anomalies. And when something is missed, a very uncomfortable question will arise: was it a failure of the employee, the procedure, the IT system, or perhaps the management board that approved an operational model without adequate safeguards? This is precisely where the boundary between compliance and personal liability blurs.</p>



<h2 class="wp-block-heading">A company&#8217;s problem can quickly become a board member&#8217;s problem</h2>



<p class="wp-block-paragraph">The Polish AML Act does not leave this solely in the realm of best practices.</p>



<p class="wp-block-paragraph">In an obliged entity where a management board operates, a person responsible for the implementation of AML duties must be designated from among its members. This is not an honorary function or a mere footnote in an organisational resolution. The Act allows for financial penalties to be imposed on persons responsible for fulfilling AML obligations. It also provides for the possibility of a temporary ban on holding managerial positions. In specific cases, breaches of reporting obligations may even lead to criminal liability.</p>



<p class="wp-block-paragraph">Naturally, a board member is not expected to personally analyse every transaction. However, they are expected to ensure that there is an efficient system, adequate resources, a clear division of responsibilities, and a realistic escalation path.</p>



<p class="wp-block-paragraph">Therefore, it is not enough to say, &#8220;We have an AML officer for that&#8221;.</p>



<p class="wp-block-paragraph">The board may delegate the execution of tasks. It cannot delegate the entire problem and then pretend that AML reports were just an exotic, graphically pleasing addition to the board meeting materials.</p>



<p class="wp-block-paragraph">Situations where the compliance unit has been signalling staff shortages, inefficient tools, backlogs in client reviews, or data quality issues for months, while the management merely notes the information and calmly moves on to the sales agenda, become particularly risky.</p>



<p class="wp-block-paragraph">Such a meeting minute may one day turn out to be more interesting than many a procedure.</p>



<h2 class="wp-block-heading">AML is becoming an element of enterprise management</h2>



<p class="wp-block-paragraph">The biggest mistake today is treating AML as an isolated regulatory island. Money laundering risk is intertwined with sanctions risk, corruption, tax, reputational, cyber risks, and the criminal liability of management.</p>



<p class="wp-block-paragraph">A new product, expansion into a foreign market, a company acquisition, a venture into digital assets, serving clients from high-risk countries, or a change in the payment model are not purely business decisions. They should also trigger questions about AML implications.</p>



<p class="wp-block-paragraph">Therefore, a properly functioning system cannot be built once and for all. It must respond to changes in the company&#8217;s operations. If the business has changed but the risk assessment remains the same, it usually does not mean the risk has been stable. It means nobody has looked at the document.</p>



<h2 class="wp-block-heading">The new boundary of liability</h2>



<p class="wp-block-paragraph">AML is no longer just about fighting a suitcase of cash brought into a bank by a man in dark glasses looking like someone from a B-movie gangster film. Today&#8217;s risk hides in multi-level ownership structures, cross-border payments, digital assets, seemingly legitimate investments, brokerage agreements, and transactions, each of which looks perfectly innocent on its own.</p>



<p class="wp-block-paragraph">Consequently, the expectations towards those responsible for the organisation are also changing. It is not enough not to know. You also have to demonstrate that the organisation did everything that could reasonably be expected of it to find out. And this is exactly where the comfortable world of compliance understood as a set of documents ends. What begins is accountability for decisions, omissions, lack of resources, and risks that nobody wanted to see.</p>



<h2 class="wp-block-heading">AML is entering new sectors today. But above all, it is entering boardrooms.</h2>



<p class="wp-block-paragraph">AML is entering new sectors today. But above all, it is entering boardrooms, and it is there that the decision is made as to whether the company truly understands its risks or merely possesses a document covering them. If you are not sure which side your organisation stands on, we will help you find out before the regulator asks.</p>



<p class="wp-block-paragraph"></p><p>The post <a href="https://lbkp.pl/en/aml-is-sailing-into-broader-waters-do-you-know-who-is-responsible-for-it-today/">AML is “sailing” into broader waters. Do you know who is responsible for it today?</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>July in LBKP</title>
		<link>https://lbkp.pl/en/july-in-lbkp/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 07:56:17 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48560</guid>

					<description><![CDATA[<p>The first half of the year is now behind us, bringing with it further publications, webinars, and expert commentary on the key changes in law, technology, and business.</p>
<p>The post <a href="https://lbkp.pl/en/july-in-lbkp/">July in LBKP</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The first half of the year is behind us, bringing with it further publications, webinars, and expert commentary on the most important changes in law, technology, and business.</p>



<p class="wp-block-paragraph">In LBKP Inside, we have brought together the most interesting materials published in June – from expert analyses and events to selected publications from the <strong>#TechnoLegals</strong> programme. We hope this newsletter serves as a convenient way for you to quickly catch up on the month&#8217;s key topics.</p>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3c6.png" alt="🏆" class="wp-smiley" style="height: 1em; max-height: 1em;" /> LBKP Among the Most Innovative Law Firms</h3>



<p class="wp-block-paragraph">This was an exceptional month for us.</p>



<p class="wp-block-paragraph">During the gala of the 24th <em>Rzeczpospolita</em> Law Firm Ranking, we were awarded distinction in the <strong>&#8220;Most Innovative Law Firms of 2025&#8221;</strong> category.</p>



<p class="wp-block-paragraph">This distinction is particularly valuable as it was awarded not for a single tool or technology, but for the way we collaborate with clients – based on <em>Embedded Legal</em>, <em>Business First Policy</em>, and <em>Legal Solutions Not Hours</em>.</p>



<p class="wp-block-paragraph">Additionally, we once again ranked in the <strong>TOP 10 largest law firms in Lower Silesia</strong>.</p>



<figure class="wp-block-image size-large"><a href="https://linkedin.com/feed/update/urn:li:activity:7472571882534305793?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="336" src="https://lbkp.pl/wp-content/uploads/2026/07/image-9-1024x336.png" alt="" class="wp-image-48102" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-9-1024x336.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-9-300x98.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-9-768x252.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-9-370x121.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-9-840x275.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-9-410x134.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-9.png 1288w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">On the Regulatory Radar</h3>



<h4 class="wp-block-heading">AI Act with Important Changes: EU Council Approves Simplification of Rules (Omnibus VII)</h4>



<p class="wp-block-paragraph">At the end of June, the Council of the European Union gave its final approval to a package of amendments simplifying the application of the AI Act. This is one of the most important regulatory decisions concerning artificial intelligence since the adoption of the regulation.</p>



<p class="wp-block-paragraph">The new rules aim to reduce administrative burdens on businesses, clarify obligations related to high-risk AI systems, and better coordinate the AI Act with sector-specific regulations.</p>



<p class="wp-block-paragraph"><strong>In brief:</strong></p>



<ul class="wp-block-list">
<li><strong>Postponed deadlines:</strong> Obligations concerning high-risk AI systems have been pushed back – for some systems, they will apply from 2 December 2027, and for systems embedded in products, from 2 August 2028.</li>



<li><strong>Bans:</strong> From December 2026, using AI to create non-consensual sexual deepfakes and child sexual abuse material will be strictly prohibited.</li>



<li><strong>Guidance:</strong> The European Commission will prepare additional guidance to help businesses implement AI Act requirements and reduce administrative burdens.</li>
</ul>



<p class="wp-block-paragraph">This is a topic we will be monitoring closely in the coming months, as the changes are of significant importance for organisations developing or utilizing AI systems.</p>



<figure class="wp-block-image size-large"><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/"><img loading="lazy" decoding="async" width="1024" height="334" src="https://lbkp.pl/wp-content/uploads/2026/07/image-10-1024x334.png" alt="" class="wp-image-48103" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-10-1024x334.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-10-300x98.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-10-768x250.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-10-370x121.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-10-840x274.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-10-410x134.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-10.png 1282w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">Expert Appearances &amp; Events</h3>



<p class="wp-block-paragraph"><strong>Marek Czwojdziński spoke at the Game Industry Conference</strong>, where he discussed the legal risks associated with using assets in video games and how studios can effectively protect their projects as early as the production stage.</p>



<p class="wp-block-paragraph"><strong>Two key aspects to keep in mind:</strong></p>



<ul class="wp-block-list">
<li>Not every &#8220;free&#8221; asset can be used without restrictions – before using one, it is advisable to verify licence terms and rights for further use.</li>



<li>Proper intellectual property management at the production stage helps mitigate the risk of disputes and costly problems after the game&#8217;s release. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/27a1.png" alt="➡" class="wp-smiley" style="height: 1em; max-height: 1em;" /> <em>View the event coverage.</em></li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7477783192951975936/?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/07/image-11-1024x332.png" alt="" class="wp-image-48105" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-11-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-11-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-11-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-11-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-11-840x272.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-11-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-11.png 1284w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<p class="wp-block-paragraph"><strong>Meanwhile, Paweł Kempa-Dymiński took part in the Re:Mind 2026 conference</strong>, joining a panel dedicated to lawyers&#8217; well-being to discuss the impact of organisational culture, AI, and generational shifts on the modern job market.</p>



<p class="wp-block-paragraph"><strong>Key takeaways for organisations:</strong></p>



<ul class="wp-block-list">
<li>Employee well-being is increasingly becoming a core element of organisational strategy – affecting not only team satisfaction, but also work quality, reduced staff turnover, and business growth.</li>



<li>Newer generations define professional success differently, making the creation of a healthy work environment one of the key challenges for modern employers.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7475934734389313536/?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="330" src="https://lbkp.pl/wp-content/uploads/2026/07/image-12-1024x330.png" alt="" class="wp-image-48106" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-12-1024x330.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-12-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-12-768x247.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-12-370x119.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-12-840x270.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-12-410x132.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-12.png 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">Cardboard Doesn&#8217;t Always Mean Eco</h3>



<h4 class="wp-block-heading">&#8220;Eco&#8221; Is Not Enough: How to Protect Your Company from Greenwashing Allegations?</h4>



<p class="wp-block-paragraph">Anna Żmidzińska and Andrzej Miziołek showed how to prepare an organisation for changes resulting from the EmpCo Directive, PPWR, and EPR (ROP), and how to reduce the risk of greenwashing when designing packaging.</p>



<p class="wp-block-paragraph"><strong>What does this mean for businesses?</strong></p>



<ul class="wp-block-list">
<li>Environmental claims must be specific, documentable, and backed by evidence – general terms like &#8220;eco&#8221; or &#8220;environmentally friendly&#8221; may soon no longer suffice.</li>



<li>Safe packaging optimisation requires collaboration not just within marketing, but also across legal, ESG, procurement, and product development departments.</li>
</ul>



<figure class="wp-block-image"><a href="https://lbkp.pl/webinar-esg-tekturowe-nie-zawsze-znaczy-eko/" target="_blank" rel="noreferrer noopener"><img decoding="async" src="https://media.licdn.com/dms/image/v2/D4D12AQFp7YmtArL92w/article-inline_image-shrink_1000_1488/B4DZ8nQJANJAAI-/0/1783069970848?e=1785369600&amp;v=beta&amp;t=InNsUWqon-FYmv0CTDw-vpUxyQHMN07x_I3IxrGvQ0I" alt=""/></a></figure>



<h3 class="wp-block-heading">Estonian CIT Debunked</h3>



<p class="wp-block-paragraph">Katarzyna Kot explained when Estonian CIT (corporate income tax) can truly be a beneficial solution, and when the classic taxation model remains the safer choice. The webinar served as a practical guide for entrepreneurs planning a change in their taxation model.</p>



<p class="wp-block-paragraph"><strong>Key takeaways from the webinar:</strong></p>



<ul class="wp-block-list">
<li>Estonian CIT is not a one-size-fits-all solution – the decision to change tax models should be preceded by an analysis of the company&#8217;s operational profile and business goals.</li>



<li>Prior to implementation, it is essential to verify entry conditions and potential risks associated with hidden profits and non-business expenses.</li>



<li>When structured properly, Estonian CIT offers numerous opportunities.</li>
</ul>



<figure class="wp-block-image"><a href="https://lbkp.pl/webinar-estonski-cit-bez-mitow/" target="_blank" rel="noreferrer noopener"><img decoding="async" src="https://media.licdn.com/dms/image/v2/D4D12AQFdqcnJIUZukg/article-inline_image-shrink_1500_2232/B4DZ8nQf82KYAQ-/0/1783070064876?e=1785369600&amp;v=beta&amp;t=2oplLL1D4kbVdC7DYP2HPLFTRww-Sr-k_ODxbITXBxQ" alt=""/></a></figure>



<h3 class="wp-block-heading">Must-Read Publications</h3>



<h4 class="wp-block-heading">AI Does Not Relieve You of Responsibility</h4>



<p class="wp-block-paragraph">Katarzyna Kot commented on the widely discussed Supreme Administrative Court (NSA) ruling regarding the use of artificial intelligence in drafting court pleadings. This is an important voice in the debate on the responsible use of AI in professions of public trust.</p>



<p class="wp-block-paragraph"><strong>What does this mean in practice?</strong></p>



<ul class="wp-block-list">
<li>AI can support a lawyer&#8217;s work, but it does not assume responsibility for verifying sources, the correctness of legal arguments, or the quality of the service provided.</li>



<li>Professionalism in the era of AI lies not in abandoning new technologies, but in using them consciously and responsibly.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7478420575120547840/?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/07/image-13-1024x332.png" alt="" class="wp-image-48107" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-13-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-13-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-13-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-13-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-13-840x273.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-13-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-13.png 1282w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h4 class="wp-block-heading">Cross-Border Disputes – Before Filing a Lawsuit</h4>



<p class="wp-block-paragraph">Is a judgment alone enough to recover debts from a foreign contractor? In our June publication, we explain why, in cross-border disputes, planning effective enforcement in advance and analysing procedures in other jurisdictions is just as critical as drafting the lawsuit itself.</p>



<p class="wp-block-paragraph"><strong>In brief:</strong></p>



<ul class="wp-block-list">
<li>Obtaining a judgment alone does not guarantee debt recovery – planning effective enforcement abroad in advance is equally important.</li>



<li>The earlier procedural and international issues are analysed, the greater the chances of actual debt recovery.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7463498399137542145/?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="329" src="https://lbkp.pl/wp-content/uploads/2026/07/image-14-1024x329.png" alt="" class="wp-image-48108" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-14-1024x329.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-14-300x96.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-14-768x246.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-14-370x119.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-14-840x269.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-14-410x132.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-14.png 1278w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h4 class="wp-block-heading">Labour Market Collusion Under the UOKiK Spotlight</h4>



<p class="wp-block-paragraph">Can non-poaching clauses violate competition law? This topic is increasingly emerging in day-to-day business practice.</p>



<p class="wp-block-paragraph"><strong>In brief:</strong></p>



<ul class="wp-block-list">
<li>Non-poach / non-solicitation clauses, which were standard contract terms just a few years ago, may now carry significant legal risks and attract scrutiny from UOKiK (Office of Competition and Consumer Protection).</li>



<li>Protecting company interests today requires solutions that are not only effective but also legally compliant – it is worth periodically reviewing standard agreements and clauses.</li>
</ul>



<figure class="wp-block-image size-large"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7471472212550639616/?originalSubdomain=pl"><img loading="lazy" decoding="async" width="1024" height="332" src="https://lbkp.pl/wp-content/uploads/2026/07/image-15-1024x332.png" alt="" class="wp-image-48109" srcset="https://lbkp.pl/wp-content/uploads/2026/07/image-15-1024x332.png 1024w, https://lbkp.pl/wp-content/uploads/2026/07/image-15-300x97.png 300w, https://lbkp.pl/wp-content/uploads/2026/07/image-15-768x249.png 768w, https://lbkp.pl/wp-content/uploads/2026/07/image-15-370x120.png 370w, https://lbkp.pl/wp-content/uploads/2026/07/image-15-840x272.png 840w, https://lbkp.pl/wp-content/uploads/2026/07/image-15-410x133.png 410w, https://lbkp.pl/wp-content/uploads/2026/07/image-15.png 1284w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<h3 class="wp-block-heading">What Lies Ahead?</h3>



<p class="wp-block-paragraph">July promises to be just as intensive.</p>



<p class="wp-block-paragraph">In the coming weeks, we will be sharing further materials for entrepreneurs and HR departments, as well as continuing our expert series.</p>



<p class="wp-block-paragraph"><strong>Follow our profiles if you are interested in:</strong></p>



<ul class="wp-block-list">
<li>➔ A new series by <strong>Paweł Kempa-Dymiński</strong> dedicated to practical aspects of employment law and the termination of employment relationships,</li>



<li>➔ Upcoming tax webinars hosted by <strong>Katarzyna Kot</strong>,</li>



<li>➔ Further events and publications on ESG, EmpCo, PPWR, and EPR (ROP) with <strong>Anna Żmidzińska</strong>,</li>



<li>➔ Expert commentary on AI and new technologies in business – check out <strong>Jacek Cieśliński</strong>, <strong>Mateusz Borkiewicz</strong>, <strong>Grzegorz Leśniewski</strong>, and <strong>Ewa Knapińska</strong> for the latest insights on AI, e-commerce, and GDPR (RODO),</li>



<li>➔ Speaking engagements by our experts at industry conferences.</li>
</ul>



<p class="wp-block-paragraph">See you in the next edition of <strong>LBKP Inside</strong>!</p><p>The post <a href="https://lbkp.pl/en/july-in-lbkp/">July in LBKP</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Tax Ordinance 2026 – a review of changes following the decisions of the President of the Republic of Poland</title>
		<link>https://lbkp.pl/en/tax-ordinance-2026-a-review-of-changes-following-the-decisions-of-the-president-of-the-republic-of-poland/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 07:50:44 +0000</pubDate>
				<category><![CDATA[Taxes en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=48557</guid>

					<description><![CDATA[<p>2026 Tax Ordinance amendments: The President vetoes statute of limitations changes but abolishes domestic MDRs. Find out what this means for entrepreneurs.</p>
<p>The post <a href="https://lbkp.pl/en/tax-ordinance-2026-a-review-of-changes-following-the-decisions-of-the-president-of-the-republic-of-poland/">Tax Ordinance 2026 – a review of changes following the decisions of the President of the Republic of Poland</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The first half of 2026 brought a number of significant changes regarding the “constitution” of the Polish tax system – the Tax Ordinance.</p>



<p class="wp-block-paragraph">On 30 April 2026, the Sejm passed the first of three amendments to the Tax Ordinance, which included significant standardisation for the publication of tax rulings issued by local government tax authorities.</p>



<p class="wp-block-paragraph">Subsequently, on 15 May 2026, the Sejm passed two further amendments to the Tax Ordinance. Their main part was due to come into force on 1 October 2026. The scope of the planned changes was broad and included both deregulatory solutions that were favourable to taxpayers, and regulations raising major doubts – primarily in the area of the statute of limitations for tax liabilities and penal fiscal liability.</p>



<p class="wp-block-paragraph">Ultimately, the fate of some of the amendments turned out differently.</p>



<p class="wp-block-paragraph">Amendments providing for:</p>



<ol start="1" class="wp-block-list">
<li>The extension of the obligation to publish local government tax rulings in the EUREKA system,</li>



<li>Simplifications for entrepreneurs, including changes to the reporting of domestic tax schemes,</li>
</ol>



<p class="wp-block-paragraph">were signed by the President of the Republic of Poland.</p>



<p class="wp-block-paragraph">On the other hand, the act encompassing changes to the suspension of the statute of limitations for tax liabilities and penal fiscal liability was vetoed.</p>



<p class="wp-block-paragraph">What does this mean for entrepreneurs and what changes should they prepare for in the coming months?</p>



<h2 class="wp-block-heading">Vetoed Tax Changes: Statute of Limitations and Penal Fiscal Code</h2>



<p class="wp-block-paragraph">One of the key proposals provided for the repeal of the controversial Article 70 § 6 point 1 of the Tax Ordinance. This provision concerns the suspension of the statute of limitations for a tax liability in connection with the initiation of penal fiscal proceedings.</p>



<p class="wp-block-paragraph">In practice, this mechanism has raised doubts among taxpayers and legal representatives for years. The initiation of penal fiscal proceedings could lead to the suspension of the statute of limitations, and thus extend the period during which the taxpayer remained in uncertainty regarding the final settlement of their tax liabilities.</p>



<p class="wp-block-paragraph">The vetoed act also included a change to the Penal Fiscal Code concerning Article 44 § 2 (specifically, its repeal). Currently, this provision serves a significant protective function, as it links the possibility of conducting penal fiscal proceedings with the expiry of the tax due itself. In other words, in certain cases, the expiry of the tax liability also limits the possibility of further prosecution for a penal fiscal offence related to that liability.</p>



<p class="wp-block-paragraph">The planned repeal of this provision sparked critical voices from some business circles. It was pointed out that the change could lead to an extension of the period of penal fiscal liability, even when the tax liability itself had already expired. The Ministry of Finance, on the other hand, argued that the proposed solution was systemically coherent and justified from the point of view of the structure of penal fiscal liability.</p>



<h3 class="wp-block-heading">Why Did the Polish President Veto the Tax Law Amendments?</h3>



<p class="wp-block-paragraph">The President of the Republic of Poland decided to veto the act encompassing changes to the Tax Ordinance and the Penal Fiscal Code. The justification for the decision emphasised the need to protect the legal security of citizens and the predictability of the state&#8217;s actions towards taxpayers.</p>



<p class="wp-block-paragraph">From the perspective of entrepreneurs, this means that the planned changes in this area will not enter into force at this point. At the same time, it should be borne in mind that the legislative procedure may still be continued. The Sejm has the power to override the President&#8217;s veto if it obtains a 3/5 majority vote in the presence of at least half of the statutory number of MPs.</p>



<h3 class="wp-block-heading">What the Presidential Veto Means for Businesses in Poland</h3>



<p class="wp-block-paragraph">The veto – in the context of one of the planned amendments – has a twofold meaning for taxpayers:</p>



<ul class="wp-block-list">
<li><strong>Firstly</strong>, the controversial Article 70 § 6 point 1 of the Tax Ordinance, used by tax authorities to instrumentally extend the statute of limitations, remains in force.</li>



<li><strong>Secondly</strong>, the current wording of Article 44 § 2 of the Penal Fiscal Code is preserved. For entrepreneurs, this means maintaining a favourable solution which, in certain situations, limits the possibility of conducting penal fiscal proceedings after the tax liability has expired.</li>
</ul>



<p class="wp-block-paragraph">In practice, taxpayers have therefore avoided one of the more controversial changes, but at the same time, there will be no repeal of the provision which has raised objections for years due to the possibility of extending tax proceedings.</p>



<h2 class="wp-block-heading">New Tax Regulations: Amendments Signed by the President</h2>



<p class="wp-block-paragraph">Regardless of the vetoed act, the President of the Republic of Poland signed two further amendments to the Tax Ordinance.</p>



<p class="wp-block-paragraph">This is a package of deregulatory and standardising changes aimed at simplifying some of the taxpayers&#8217; obligations, streamlining day-to-day relations with the tax administration and standardising tax knowledge bases.</p>



<h3 class="wp-block-heading">The End of Domestic MDR Reporting in Poland</h3>



<p class="wp-block-paragraph">One of the most important changes is the abolition of the obligation to report domestic tax schemes, i.e., so-called domestic MDRs (Mandatory Disclosure Rules).</p>



<p class="wp-block-paragraph">Until now, MDR obligations were a significant organisational burden for many entrepreneurs, advisors, and accountants. They required the analysis of many economic events in terms of a potential reporting obligation, even in situations concerning exclusively domestic transactions.</p>



<p class="wp-block-paragraph">The amendment aims to limit this obligation. It should be clearly emphasised, however, that the simplification concerns domestic tax schemes. <strong>The obligation to report cross-border schemes remains in force.</strong></p>



<h3 class="wp-block-heading">Simplified Tax Settlements and Facilitations with the Tax Office</h3>



<p class="wp-block-paragraph">The amendment also provides for a number of minor changes aimed at simplifying day-to-day tax settlements.</p>



<p class="wp-block-paragraph">One of them is raising the limit of the tax amount that can be paid on behalf of another taxpayer – from PLN 1,000 to PLN 5,000. This change may have practical significance, e.g., in corporate groups, family businesses, and in situations where tax settlements are organisationally handled by another entity.</p>



<p class="wp-block-paragraph">The new regulations are also to concern the rules of accounting for interest and procedures related to the refund of stamp duty and tax overpayments. The aim of these changes is to reduce minor formalities and speed up the handling of simpler tax matters.</p>



<h2 class="wp-block-heading">EUREKA System: A Centralised Database for Local Tax Rulings</h2>



<p class="wp-block-paragraph">Additionally, the amendment provides for the standardisation of the rules for publishing tax rulings concerning local taxes and charges. Rulings issued by heads of rural municipalities (<em>wójts</em>), mayors, and city presidents are to be made available in a single database maintained by the Director of the National Revenue Information (the so-called EUREKA System).</p>



<p class="wp-block-paragraph">This solution should make it easier for taxpayers to search for them and compare the positions of individual authorities. Until now, the publication of such rulings was dispersed across the websites of the administrative offices supporting the local government authorities issuing the rulings.</p>



<h2 class="wp-block-heading">How to Prepare for the Upcoming Tax Changes in Poland?</h2>



<p class="wp-block-paragraph">Entrepreneurs should, first and foremost, verify how the signed amendment will affect their obligations regarding MDR and day-to-day settlements with the tax office.</p>



<p class="wp-block-paragraph">It is also worth monitoring the further fate of the vetoed act, as a potential overriding of the veto by the Sejm could reopen the path to changes in the scope of the statute of limitations and penal fiscal liability.</p>



<p class="wp-block-paragraph">At LBKP, we continuously analyse tax changes and their impact on entrepreneurs. Contact us if you want to streamline your tax procedures, verify your MDR obligations, or prepare your company for the new regulations.</p><p>The post <a href="https://lbkp.pl/en/tax-ordinance-2026-a-review-of-changes-following-the-decisions-of-the-president-of-the-republic-of-poland/">Tax Ordinance 2026 – a review of changes following the decisions of the President of the Republic of Poland</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Estonian CIT and Dividend Payouts: Tax Base and PIT Deduction Mechanism</title>
		<link>https://lbkp.pl/en/estonian-cit-and-dividend-payouts-tax-base-and-pit-deduction-mechanism/</link>
		
		<dc:creator><![CDATA[Admin]]></dc:creator>
		<pubDate>Thu, 25 Jun 2026 12:38:15 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=47977</guid>

					<description><![CDATA[<p>How are dividends taxed under Estonian CIT? Learn how to calculate the tax base and apply the PIT deduction mechanism correctly. Read our guide!</p>
<p>The post <a href="https://lbkp.pl/en/estonian-cit-and-dividend-payouts-tax-base-and-pit-deduction-mechanism/">Estonian CIT and Dividend Payouts: Tax Base and PIT Deduction Mechanism</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">Estonian CIT (lump-sum tax on corporate income) has been an alternative to traditional corporate income tax since 2021. Its most crucial feature is shifting the moment of taxation—as a rule, a company does not pay tax on an ongoing basis from its generated profits, but only when those profits are distributed to shareholders or when another taxable event occurs.</p>



<p class="wp-block-paragraph">In practice, most questions arise during dividend payouts. This is precisely when tax obligations arise for both the company and the shareholder. Properly establishing the tax base and correctly applying the PIT deduction mechanism provided for in the PIT Act is therefore of key importance.</p>



<h2 class="wp-block-heading"><strong>How is a Dividend Taxed Under Estonian CIT?</strong> </h2>



<p class="wp-block-paragraph">Under the Estonian CIT model, taxation at the corporate level occurs, as a rule, only at the time of profit distribution. As long as the funds remain within the company and are used for its business operations, no tax liability arises from the distributed profit. However, it is important to remember that the law also provides for other categories of taxable income, such as hidden profits or expenses unrelated to business activities.</p>



<p class="wp-block-paragraph">When it comes to Estonian CIT on profit distribution, the lump-sum tax rate depends on the taxpayer&#8217;s status. For small taxpayers and start-ups, it is <strong>10%</strong> of the tax base. Other taxpayers apply a <strong>20%</strong> rate.</p>



<p class="wp-block-paragraph">However, the settlement does not end there. A dividend payout also generates income for a shareholder who is an individual. This income is subject to a <strong>19%</strong> flat-rate PIT.</p>



<p class="wp-block-paragraph">Nevertheless, this does not mean that the same profit is fully taxed twice. The structure of the Estonian CIT includes a mechanism that limits the economic burden of double taxation. It consists of reducing the PIT due from the shareholder by a corresponding portion of the lump-sum tax paid by the company.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://lbkp.pl/wp-content/uploads/2026/06/2151612635-1024x574.jpg" alt="estoński cit" class="wp-image-47974" srcset="https://lbkp.pl/wp-content/uploads/2026/06/2151612635-1024x574.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-300x168.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-768x430.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-1536x861.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-370x207.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-410x230.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-840x471.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635-270x152.jpg 270w, https://lbkp.pl/wp-content/uploads/2026/06/2151612635.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading"><strong>How Does the PIT Deduction Work?</strong> </h2>



<p class="wp-block-paragraph">In the case of a dividend paid from profits earned during the period of Estonian CIT taxation, the shareholder&#8217;s PIT can be reduced by a portion of the corporate lump-sum tax components attributable to that shareholder.</p>



<p class="wp-block-paragraph">In practice, this means that:</p>



<ul class="wp-block-list">
<li><strong>With a 10% corporate tax rate</strong>, the shareholder can deduct <strong>90%</strong> of their share of the corporate lump-sum tax.</li>



<li><strong>With a 20% corporate tax rate</strong>, the shareholder can deduct <strong>70%</strong> of their share of the corporate lump-sum tax.</li>
</ul>



<p class="wp-block-paragraph">The amount of the deduction is therefore linked to the shareholder&#8217;s share in the profit and the lump-sum tax rate applied by the company.</p>



<p class="wp-block-paragraph">A condition for applying this mechanism is, among other things, that the payout concerns profits generated during the period of corporate lump-sum taxation and properly separated within the company&#8217;s equity.</p>



<h2 class="wp-block-heading"><strong>Gross Profit Amount or the Amount After Estonian CIT Deduction?</strong> </h2>



<p class="wp-block-paragraph">In practice, taxpayers often wonder what amount should be used to calculate PIT on a dividend paid from profits taxed under Estonian CIT. The doubt boils down to the question: is the PIT base the gross amount of profit allocated for distribution, or the amount reduced by the lump-sum tax due from the company?</p>



<p class="wp-block-paragraph">The current approach of tax authorities and administrative courts is quite clear in this regard. <strong>The PIT tax base should be the full (gross) amount of profit allocated for distribution</strong>, without prior reduction by the Estonian CIT due from the company. </p>



<p class="wp-block-paragraph">Consequently, the correct order of settlement is as follows:</p>



<ol start="1" class="wp-block-list">
<li>The company determines the net profit amount allocated for distribution.</li>



<li>The company calculates the corporate lump-sum tax due on this amount.</li>



<li>The company calculates the shareholder&#8217;s <strong>19% PIT</strong> based on the full dividend amount.</li>



<li>Finally, the company reduces the PIT by the appropriate portion of the lump-sum tax paid by the company.</li>
</ol>



<p class="wp-block-paragraph">Therefore, it would be incorrect to first reduce the dividend by the Estonian CIT and only then calculate the 19% PIT on that reduced amount. Such an action could lead to an underpayment of the tax collected by the company acting as the tax remitter.</p>



<h2 class="wp-block-heading">Tax Calculation Example</h2>



<p class="wp-block-paragraph">Assume that a company allocates <strong>PLN 100,000</strong> of profit generated during the Estonian CIT period for payout to its sole shareholder.</p>



<h2 class="wp-block-heading">Scenario 1: The company applies the 10% rate</h2>



<p class="wp-block-paragraph">Corporate lump-sum tax:</p>



<p class="wp-block-paragraph">$$10\% \times \text{PLN } 100,000 = \text{PLN } 10,000$$</p>



<p class="wp-block-paragraph">PIT on dividend before deduction:</p>



<p class="wp-block-paragraph">$$19\% \times \text{PLN } 100,000 = \text{PLN } 19,000$$</p>



<p class="wp-block-paragraph">Deduction:</p>



<p class="wp-block-paragraph">$$90\% \times \text{PLN } 10,000 = \text{PLN } 9,000$$</p>



<p class="wp-block-paragraph">PIT to be collected from the shareholder:</p>



<p class="wp-block-paragraph">$$\text{PLN } 19,000 &#8211; \text{PLN } 9,000 = \text{PLN } 10,000$$</p>



<p class="wp-block-paragraph"><strong>Total tax burden:</strong> PLN 20,000, which constitutes <strong>20%</strong> of the profit allocated for distribution.</p>



<h2 class="wp-block-heading">Scenario 2: The company applies the 20% rate </h2>



<p class="wp-block-paragraph">Corporate lump-sum tax:$$20\% \times \text{PLN } 100,000 = \text{PLN } 20,000$$</p>



<p class="wp-block-paragraph">PIT on dividend before deduction:$$19\% \times \text{PLN } 100,000 = \text{PLN } 19,000$$</p>



<p class="wp-block-paragraph">Deduction:$$70\% \times \text{PLN } 20,000 = \text{PLN } 14,000$$</p>



<p class="wp-block-paragraph">PIT to be collected from the shareholder:$$\text{PLN } 19,000 &#8211; \text{PLN } 14,000 = \text{PLN } 5,000$$</p>



<p class="wp-block-paragraph"><strong>Total tax burden:</strong> PLN 25,000, which constitutes <strong>25%</strong> of the profit allocated for distribution.</p>



<h2 class="wp-block-heading"><strong>Summary</strong> </h2>



<p class="wp-block-paragraph">When paying out a dividend from profits taxed under Estonian CIT, the correct sequence of calculations is critical. The shareholder&#8217;s PIT must be calculated from the full amount of profit allocated for distribution, and only then should the statutory deduction of a portion of the corporate lump-sum tax be applied.</p>



<p class="wp-block-paragraph">In practice, this means that Estonian CIT does not eliminate dividend taxation on the shareholder&#8217;s side, but it significantly reduces the overall tax burden. For small taxpayers, the effective taxation of distributed profit is generally <strong>20%</strong>, and for other taxpayers, it is <strong>25%</strong>.</p>



<h2 class="wp-block-heading">Got Questions?</h2>



<p class="wp-block-paragraph">Do you need support with Estonian CIT or have doubts regarding the taxation of profit distribution? Contact us. We will help analyze your company&#8217;s situation, correctly establish the tax base, and safely settle your dividend.</p><p>The post <a href="https://lbkp.pl/en/estonian-cit-and-dividend-payouts-tax-base-and-pit-deduction-mechanism/">Estonian CIT and Dividend Payouts: Tax Base and PIT Deduction Mechanism</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity in local government – from a technical issue to a board agenda item</title>
		<link>https://lbkp.pl/en/47499-2/</link>
		
		<dc:creator><![CDATA[Paulina Jeziorska]]></dc:creator>
		<pubDate>Thu, 07 May 2026 09:02:29 +0000</pubDate>
				<category><![CDATA[CyberSec & FinTech en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=47499</guid>

					<description><![CDATA[<p>The amended Act on the National Cybersecurity System, implementing the NIS2 Directive, has been in&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/47499-2/">Cybersecurity in local government – from a technical issue to a board agenda item</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<p class="wp-block-paragraph">The amended Act on the National Cybersecurity System, implementing the NIS2 Directive, has been in force since 3 April. The debate on the new obligations has focused mainly on the private sector – and wrongly so. The regulation also covers public entities, including local government bodies, their organisational units and municipal companies.</p>



<p class="wp-block-paragraph">Our experts Paulina Jeziorska and Zuzanna Prandecka-Walek have analysed this topic in Dziennik Gazeta Prawna. In the article, they discuss step by step what the amendment means in practice for local authorities – from determining who is subject to the new regulations, through the catalogue of obligations, to the sanctions regime.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="439" src="https://lbkp.pl/wp-content/uploads/2026/05/2673-1024x439.jpg" alt="" class="wp-image-47496" srcset="https://lbkp.pl/wp-content/uploads/2026/05/2673-1024x439.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/05/2673-300x129.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/05/2673-768x329.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/05/2673-1536x658.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/05/2673-370x159.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/05/2673-840x360.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/05/2673-410x176.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/05/2673.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">A few points worth noting:</h2>



<p class="wp-block-paragraph">A new classification of entities. The previous model, which distinguished between operators of key services and digital service providers, is being replaced by a classification into key entities and important entities. In the case of local authorities, the decisive factor is not the scale of their operations, but the type of authority and its position within the structure. Key entities include, amongst others, district authorities and local councils employing at least 50 people. Important entities, in turn, include local government budgetary units, budgetary institutions, cultural institutions and municipal companies – provided they carry out public tasks using information systems.</p>



<p class="wp-block-paragraph">The obligations go far beyond mere formalities. Implementing an information security management system, handling and reporting incidents, ensuring business continuity, and streamlining relations with suppliers – this is not a one-off project, but a permanent change in the way the organisation operates. For important entities that are public bodies, the legislator has also provided a specific list of minimum requirements in an annex to the Act.</p>



<p class="wp-block-paragraph">The penalties are substantial. Fines can reach up to €10 million for critical entities and €7 million for important entities. The head of the entity is held personally liable – up to 100% of their salary in the case of public entities. The regulations grant the authority some flexibility in determining the penalty, taking into account, among other things, the entity’s financial capacity, but the lower thresholds are set by law.</p>



<p class="wp-block-paragraph">A key point of interpretation: is a key entity that does not use information systems to carry out public tasks completely exempt from these obligations? The wording of the regulations does not provide a clear answer, which in practice may create uncertainty for local authorities.</p>



<p class="wp-block-paragraph">For many local authorities, the coming months will test their ability to rapidly build up the expertise and structures that they simply have not needed until now. Putting this off is no longer an option.</p>



<h2 class="wp-block-heading">The full article by Paulina Jeziorska and Zuzanna Prandecka-Walek is available in Dziennik Gazeta Prawna:</h2>



<div class="wp-block-essential-blocks-button  root-eb-button-4tojd"><div class="eb-parent-wrapper eb-parent-eb-button-4tojd "><div class="eb-button-wrapper eb-button-alignment eb-button-4tojd"><div class="eb-button"><div class="eb-button-inner-wrapper "><a class="eb-button-anchor  " href="https://edgp.gazetaprawna.pl/samorzad/cyfryzacja-i-e-uslugi-publiczne/artykuly/11226093,cyberbezpieczenstwo-nowe-obowiazki-uderza-rowniez-w-podmioty-publiczn.html" rel="noopener">Link to the full article</a></div></div></div></div></div><p>The post <a href="https://lbkp.pl/en/47499-2/">Cybersecurity in local government – from a technical issue to a board agenda item</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your game could be a high-risk system. The AI Act and what game developers don’t yet know</title>
		<link>https://lbkp.pl/en/your-game-could-be-a-high-risk-system-the-ai-act-and-what-game-developers-dont-yet-know/</link>
		
		<dc:creator><![CDATA[Marek Czwojdziński]]></dc:creator>
		<pubDate>Fri, 24 Apr 2026 10:27:16 +0000</pubDate>
				<category><![CDATA[NewTech Law en]]></category>
		<guid isPermaLink="false">https://lbkp.pl/?p=47474</guid>

					<description><![CDATA[<p>Are the algorithms in your game subject to the AI Act? Most game development studios&#8230;</p>
<p>The post <a href="https://lbkp.pl/en/your-game-could-be-a-high-risk-system-the-ai-act-and-what-game-developers-dont-yet-know/">Your game could be a high-risk system. The AI Act and what game developers don’t yet know</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></description>
										<content:encoded><![CDATA[<h2 class="wp-block-heading">Are the algorithms in your game subject to the AI Act? Most game development studios assume they aren’t. Most of them are wrong.</h2>



<p class="wp-block-paragraph">In 2018, the Belgian Gaming Commission classified loot boxes as gambling and banned their sale for real money. Not because they were illegal under gambling law (lawyers argued about this for a long time), but because a mechanism that requires payment for a random chance of winning, aimed at children, is in practice a slot machine. Major studios, including Blizzard and EA, had to withdraw paid loot boxes from the Belgian market. However, enforcing the ban proved difficult and loot boxes continue to operate in Belgium to this day, but the precedent was clear – the regulator stated that the gaming industry’s business model could constitute gambling, and they were right. Despite strict regulations, research from 2021–2022 suggested that the ban was not fully enforced across all mobile games; however, the major studios (EA, Blizzard, Nintendo) complied with the requirements to avoid heavy financial penalties or even criminal liability.</p>



<p class="wp-block-paragraph">In a few months’ time, a similar debate on the limits of the law will take place across the European Union, but this time it is not about gambling but the AI Act. A system that matches opponents to a player’s profile, a shop displaying offers at the perfect moment, a mechanism that calibrates difficulty so that the player does not give up – all of the above – if it analyses user data and makes decisions on that basis – constitutes AI within the meaning of the<a href="https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX:32024R1689" target="_blank" rel="noreferrer noopener"> AI Act</a> and falls under the scope of that legislation.</p>



<h2 class="wp-block-heading">When a game algorithm ceases to be a mechanic and becomes an AI system in the legal sense</h2>



<p class="wp-block-paragraph">The AI Act defines an AI system by what it does, not by what it is called. If a system analyses user data and, on that basis, generates predictions, recommendations or decisions that influence the user’s behaviour, we have an AI system within the meaning of the law – regardless of whether the studio has called it an algorithm, a recommendation engine, or anything else. The line is not drawn where the industry is accustomed to drawing it, and this is precisely the source of a problem that most studios have yet to recognise.</p>



<p class="wp-block-paragraph">Over the years, player matching algorithms have evolved from simply comparing statistics to models that analyse behavioural data, a player’s frustration levels, their spending history and susceptibility to a loss of control. As long as they served to improve gameplay quality, nobody had a problem with such mechanisms. The problem arises when the same data begins to be used to influence purchasing decisions, because that is when we enter an area that is explicitly prohibited by the AI Act. Systems designed to alter a user’s behaviour without their knowledge in a way that could cause them harm have been banned since February 2025, and the line between personalisation and manipulation is rarely clear-cut; it is precisely this line that will be the subject of the first major disputes between the regulator and the industry.</p>



<p class="wp-block-paragraph">Dynamic pricing has been used in games for years and is rarely seen as a legal issue; however, players should be aware that the offer they see is not the same as the one someone else sees, and that the algorithm has made this decision based on their data. At the moment the player makes their choice, no one points this out to them or informs them of it.</p>



<p class="wp-block-paragraph">As research published by<a href="https://www.gry-online.pl/newsroom/lootboxy-to-jednak-hazard-rujnujacy-niezamoznych-graczy-nowe-usta/za1f8d7" target="_blank" rel="noreferrer noopener"> BeGambleAware</a> shows, just 5% of players generate half of the market revenue from loot boxes, suggesting that these systems exploit the behavioural biases of a specific group of users rather than relying on the informed purchasing decisions of the player base as a whole. If the algorithm adjusts the probability of items being drawn to match a player’s profile and spending history, the studio must be able to prove that the system does not employ manipulative techniques.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="574" src="https://lbkp.pl/wp-content/uploads/2026/04/12157-1-1024x574.jpg" alt="" class="wp-image-47471" srcset="https://lbkp.pl/wp-content/uploads/2026/04/12157-1-1024x574.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-300x168.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-768x430.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-1536x861.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-370x207.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-410x230.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-840x471.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1-270x152.jpg 270w, https://lbkp.pl/wp-content/uploads/2026/04/12157-1.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">Children’s games – a separate category of risk that must not be ignored</h2>



<p class="wp-block-paragraph">This is the most challenging area and the one where the consequences could be the most serious. Games aimed at children or those played by large numbers of children, which use algorithms to optimise engagement and retention, may require a fundamental rights impact assessment before they are placed on the EU market, as the AI Act treats systems that may affect minors particularly strictly. An algorithm that analyses a child’s behaviour in order to extend their gaming session and increase the likelihood of a purchase is a system that may affect the fundamental rights of a minor. The situation is complicated by the fact that the<a href="https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679" target="_blank" rel="noreferrer noopener"> GDPR</a> and the<a href="https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX:32022R2065" target="_blank" rel="noreferrer noopener"> DSA</a> both impose their own obligations on users under the age of eighteen, meaning that a studio developing a children’s game with an advanced retention system could find itself subject to three different regulatory regimes at the same time, and none of them will be willing to accept that it was merely an innocent part of the game.</p>



<h2 class="wp-block-heading">What do game developers need to document and report?</h2>



<p class="wp-block-paragraph">For low-risk AI systems, the requirements are modest, but they do exist, as users interacting with a generative AI system must be aware of this, and a shop powered by a recommendation algorithm should operate in a way that is understandable to the user. In contrast, for systems classified as high-risk, the scope of obligations is much broader, as it includes implementing a risk management system throughout the product lifecycle, maintaining technical documentation, ensuring automatic event logging and human oversight of important system decisions, and registering the system in the<a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai" target="_blank" rel="noreferrer noopener"> EU database</a> prior to deployment. All of this requires planning at the level of the entire game development process.</p>



<p class="wp-block-paragraph">There is one further issue that the industry regularly overlooks. A studio that uses off-the-shelf AI tools from an external supplier and implements them under its own brand or adapts them to its own purposes may be considered an AI system provider rather than merely a user, thereby bearing the full scope of a provider’s responsibilities, including conformity assessment and registration. A studio that takes a ready-made AI tool and configures it for its own use cannot assume that the responsibility for regulatory compliance lies with the provider, as this is not the case under the AI Act.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="575" src="https://lbkp.pl/wp-content/uploads/2026/04/1778852-1024x575.jpg" alt="gamedev AI Act" class="wp-image-47472" srcset="https://lbkp.pl/wp-content/uploads/2026/04/1778852-1024x575.jpg 1024w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-300x169.jpg 300w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-768x432.jpg 768w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-1536x863.jpg 1536w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-370x208.jpg 370w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-1290x725.jpg 1290w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-840x472.jpg 840w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-410x230.jpg 410w, https://lbkp.pl/wp-content/uploads/2026/04/1778852-270x152.jpg 270w, https://lbkp.pl/wp-content/uploads/2026/04/1778852.jpg 2000w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h2 class="wp-block-heading">How can a game development studio prepare for the requirements of the AI Act before the regulations come into force?</h2>



<p class="wp-block-paragraph">The starting point is to identify which elements of the game actually analyse player data and do something with it, as this is where risk classification begins. For each such element, it is worth checking whether it could influence the player’s financial decisions, whether it is aimed at children, whether it analyses behavioural or emotional data, and whether it might operate in ways of which the player is unaware. The more affirmative answers there are, the higher the risk classification and the broader the scope of obligations.</p>



<p class="wp-block-paragraph">Added to this is a review of contracts with external AI tool providers, as those signed before 2025 almost certainly do not regulate the division of liability in the event of a query from the regulator. This is a mistake that is easy to rectify now but difficult to explain later. For years, the game development industry had plenty of scope for innovation before regulation caught up with technology. In the case of the AI Act, that window has closed; the regulations are in force and penalties can reach 7% of global annual turnover. A studio that carries out an analysis now has time to adapt calmly. One that waits will only discover the extent of the problem when it already has to act quickly.</p>



<h5 class="wp-block-heading">If you would like to discuss this, please do not hesitate to contact us. </h5><p>The post <a href="https://lbkp.pl/en/your-game-could-be-a-high-risk-system-the-ai-act-and-what-game-developers-dont-yet-know/">Your game could be a high-risk system. The AI Act and what game developers don’t yet know</a> first appeared on <a href="https://lbkp.pl">Kancelaria LBKP</a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
