Practice Areas
I. Digital & Technology Regulation
Artificial Intelligence (AI Act)
The EU Artificial Intelligence Act is the world’s first comprehensive legal framework for the
development, deployment and use of AI systems. For many organisations it represents a
fundamental shift that requires legal, organisational and technical readiness in parallel.
The Act classifies AI systems by risk level – prohibited practices, high-risk systems, limited-risk
systems and minimal-risk systems – with the strictest obligations falling on high-risk systems and
on providers of general-purpose AI models. We guide providers, deployers and other obliged
parties through the entire adaptation process.
What we offer
– Regulatory mapping and classification of AI systems by risk level
– Gap analysis and a practical AI Act readiness roadmap aligned with the latest application
timelines
– AI governance frameworks, policies and internal procedures
– Fundamental Rights Impact Assessments (FRIA) and identification of general-purpose AI
(GPAI) obligations
– Alignment of AI development and deployment with transparency, data-quality, human-
oversight and documentation requirements
– Drafting and adapting contracts, terms of use and legal documentation for AI
– Integrating the AI Act with GDPR, cybersecurity and product-liability requirements
Digital Operational Resilience (DORA)
DORA strengthens the digital resilience of the financial system and ensures that financial entities
and their technology providers can withstand, respond to and recover from cyber incidents and ICT
disruptions.
Compliance requires integration across financial regulation, cybersecurity, technology governance,
vendor contracts and risk management. Many organisations struggle to translate the requirements
into practical, day-to-day implementation – this is where we help.
Who it is for
– Banks and financial institutions
– Investment firms, brokerage houses and investment funds
– Payment and e-money institutions and fintech companies
– Insurance and reinsurance undertakings
– ICT third-party service providers, including cloud, SaaS and cybersecurity companies
What we offer
– Regulatory mapping and gap analysis against DORA and its delegated RTS/ITS
– ICT risk-management frameworks, policies and procedures
– ICT-incident classification, management and reporting processes
– Digital operational resilience testing, including threat-led penetration testing (TLPT)
– Third-party risk oversight and alignment of ICT contracts with DORA requirements
– Preparation for supervisory reviews and regulatory reporting
Cybersecurity (NIS2 / National Cybersecurity System – KSC)
The NIS2 Directive and the Polish National Cybersecurity System (KSC) significantly expand the
circle of obligated entities and raise the bar for cybersecurity risk management, incident handling
and management-body accountability.
We help essential and important entities – as well as public-sector bodies and local-government
units – determine whether and how they are covered, and put in place a compliant and workable
cybersecurity scheme.
What we offer
– Assessment of whether the organisation qualifies as an essential or important entity
– Gap analysis against NIS2 / KSC obligations and a remediation plan
– Cybersecurity risk-management policies, procedures and governance
– Incident-handling and reporting processes aligned with statutory deadlines
– Supply-chain and vendor-security requirements
– Training and awareness programmes, including for management bodies
I. Digital & Technology Regulation
II. Data Protection & Privacy
GDPR Compliance
Data protection sits at the centre of modern regulatory practice and intersects with almost every
other obligation – from AI and cybersecurity to financial-sector and employment requirements.
We accompany organisations from initial assessment through full implementation, and we support
clients in crisis situations such as data breaches and the proceedings that follow.
What we offer
– Data-protection maturity assessments, gap analysis and GDPR readiness plans
– Preparation of external documentation (privacy notices, information clauses) and internal
documentation (records, policies, procedures)
– Opinions on complex processing operations, including DPIA, LIA and TIA, and on international
data transfers
– Support and representation in proceedings and inspections before the supervisory authority
(PUODO)
– Crisis management and handling of personal-data breaches
– Reconciling data protection with the EU AI Act and sector-specific regulation
Data Protection Officer (DPO) as a Service
Data Protection Officer (DPO) as a Service
Outsourcing the DPO function gives you access to experienced privacy and information-security
specialists without the cost and overhead of an in-house team.
Acting as your DPO – or advising your internal DPO – we help you run the business confidently
and efficiently while remaining fully aligned with GDPR requirements.
What we offer
– Performing the statutory DPO role or advising your in-house DPO
– Monitoring compliance and maintaining the records of processing activities
– Handling data-subject requests and complaints
– Cooperating with and acting as the contact point for the supervisory authority
– Ongoing training and awareness across the organisation
III. Financial Services Regulation & AML
Financial Services Regulation (MiFID II)
We advise investment firms, banks and other market participants on the full spectrum of EU
financial-services regulation, with deep, first-hand knowledge of how the supervisor thinks and
acts.
Our experience spans MiFID II, market-conduct and investor-protection requirements, product
governance, reporting obligations and the wider EU regulatory toolkit.
What we offer
– Authorisation, licensing and ongoing regulatory advisory under MiFID II
– Product governance, suitability and appropriateness, and conduct-of-business requirements
– Transaction- and trade-reporting obligations (EMIR, MiFIR, SFTR) and reform readiness
– Internal policies, procedures and compliance frameworks for investment services
– Support during supervisory inspections and administrative proceedings
– Regulatory horizon-scanning and impact analysis
Anti-Money Laundering (AML/CFT)
The central challenge of AML and CFT is reconciling strict regulatory compliance with a
competitive market position. We act for obliged institutions across sectors, guiding them through
supervisory inspections and representing them in administrative proceedings.
Our work draws on hands-on experience inside obliged institutions and on the supervisory side,
including the role of AML Reporting Officer.
What we offer
– Implementation and audit of AML/CFT systems, including risk-assessment methodologies and
the internal risk assessment
– Design of customer risk-assessment processes and proportionate financial-security measures
– Opinions on AML issues, including remote identity verification, beneficial-ownership rules and AML outsourcing
– Support during GIIF inspections and administrative proceedings
– AML outsourcing for non-banking obliged entities
– Training for management, supervisory boards and internal AML teams
III. Financial Services Regulation & AML
IV. Corporate Compliance & Governance (GRC)
Compliance Officer as a Service
A well-designed compliance system protects the organisation, supports its development and
reduces the risk of liability for owners, officers and managers – while minimising the risk of
penalties and financial loss.
Our regulatory and technical experts establish the compliance scheme, implement policies and
procedures, deliver training, run internal audits and reviews, guide the business units, report to
management on the compliance state, and monitor new regulatory and standards requirements.
What we offer
– Building and maintaining compliance systems in line with best practice in regulated sectors
– Preparation and implementation of core compliance procedures – contractor verification,
conflict-of-interest management and purchasing policies
– Mapping regulatory requirements relevant to the organisation and translating them into
actionable instructions
– Audits and assessments of existing compliance systems
– Compliance programmes and training
– Reporting to management and preparation for external audits by regulators and customers
Whistleblowing & Anti-Corruption
Whistleblower protection and anti-corruption are now core compliance obligations rather than
optional add-ons. We help organisations meet their statutory duties while building a culture that
surfaces issues before they become critical.
Our advice is grounded in dedicated authorship and practice on whistleblowing and anti-corruption
frameworks.
What we offer
– Whistleblowing procedures and internal reporting channels compliant with statutory
requirements
– Anti-corruption policies, gift-and-hospitality rules and conflict-of-interest frameworks
– Handling, triage and follow-up of internal reports
– Training for management, reporting officers and employees
– Reviews and audits of existing whistleblowing and anti-corruption schemes
ESG & Sustainability
Sustainability regulation is moving rapidly from voluntary commitment to binding obligation, with
significant disclosure, governance and supply-chain consequences for in-scope organisations.
We help clients understand whether and how the new requirements apply, and integrate them with
their existing compliance and reporting frameworks.
What we offer
– Assessment of ESG and sustainability obligations applicable to the organisation
– Sustainability disclosure and reporting readiness
– Governance, policies and internal procedures for ESG
– Integration of ESG requirements with the wider compliance framework
– Training and management briefings
IV. Corporate Compliance & Governance (GRC)
V. Firearms & Administrative Law
Firearms Law (access to firearms)
Access to firearms in Poland is governed by the Act on Weapons and Ammunition together with a
dense web of implementing regulations, and is administered by the Police. The process is to a
large extent discretionary, and disputes frequently reach the administrative courts.
We advise individuals, collectors, shooting clubs and businesses on obtaining, maintaining and
defending firearms permits, and we represent clients throughout administrative proceedings and
before the administrative courts. Our work in this area is backed by dedicated authorship – the first
comprehensive Polish treatment of the law of access to firearms.
What we offer
– Applications for firearms permits (sport, hunting, collector, personal-protection and other
grounds) and supporting documentation
– Representation before the Police authorities and in administrative proceedings
– Appeals and complaints to the administrative courts, including complaints against authority
inaction
– Advice on the obligations of permit holders – registration, storage and carrying of firearms
– Public-information access requests and litigation concerning firearms-permit practice
– Regulatory support for shooting ranges, clubs and dealers