MICHAŁ RUTKOWSKI
DPO, GDPR, NIS2 and Cybersecurity for Medium and Large Organizations
I help management boards and teams responsible for data and security to organize risks, obligations and actions. I combine DPO and GDPR support, NIS2, incident handling and training.

Over 20 years of experience
Technology experience, data protection, and cybersecurity since 2004.
DPO + IT + Cybersecurity
Combining legal, organizational, technical and operational perspectives.
Medium and Large Organizations
Support for management boards and legal, compliance, IT and security teams.
From Assessment to Action
Audits, incident handling, and implementations translated into decisions, actions, and organized evidence.
How can I help?
Choose the area that corresponds to your organization’s current situation. If you don’t know where to start, a diagnostic conversation can be the first step.
DPO and GDPR
External DPO, support for the current officer, GDPR audit and ongoing advice for management and teams.
NIS2 and local law KSC
NIS2 and local law KSC qualification, gap and risk analysis, plan, and support for implementation and audit readiness.
Incidents and Breaches
Situation and risk assessment, decisions regarding notifications, communication, and remedial actions.
Training and Workshops
Practical GDPR and NIS2 training for management boards, executives, employees and IT and compliance teams.
When is it worth talking?
It’s worth talking when obligations, risks, or business expectations require organization and concrete decisions.
You don’t need a ready diagnosis
Initially, a general description of the situation, without confidential information, is sufficient. Together, we will determine whether a consultation, audit, implementation project, or ongoing support is needed.
External DPO
The organization needs an external DPO or additional support for its current officer.
NIS2 and local law KSC
It is necessary to define the scope of obligations and translate requirements into responsibilities and an action plan.
Incident or Breach
An incident has occurred, or there is a suspicion of a data breach.
Documentation vs. Practice
Documentation does not reflect actual processes, systems, or responsibilities.
Client Requirements
A client, contractor, or auditor expects confirmation of data protection methods or security levels.
Management Decisions
Management needs a risk assessment, priorities, and a concrete plan for further actions.
How does cooperation work?
Cooperation is structured, predictable, and adapted to the actual risks and operating methods of the organization.

01. Situation Assessment
A brief conversation, gathering context and identifying key needs, risks, and limitations.

02. Scope and Priorities
Defining responsibilities, expected outcomes, timeline and order of actions.

03. Implementation
Audit, analysis, consultations, documentation preparation, implementation, or incident handling, depending on the agreed scope.

04. Maintenance and Support
Monitoring the implementation of agreements, supporting management and updating solutions along with changes in the organization and legal environment.
Experience in Complex Organizations
I support organizations where local requirements combine with group policies, technology and management responsibility.
Selected organizations I have supported or collaborated with. The scope of individual projects varied.
INDIGO Polska S.A.

Digital Virgo Polska Sp. z o.o.

Polskie Linie Oceaniczne S.A.

EPQS Sp. z o.o.

Hotel Dom Marynarza

Independent Logistics Sp. z o.o.
Selected Experiences
Examples illustrate the approach – from assessing the situation and risk, through organizing decisions, to implementing concrete actions.
Handling a Breach and Notification to UODO
Situation: A serious incident requiring rapid risk assessment and a decision regarding notification to the supervisory authority.
Action: Event analysis, documentation preparation, communication support, notification to UODO, and a plan of remedial actions.
Result: Organized organizational response, documented decisions, and implemented measures to reduce the risk of recurrence.
Consistent Data Management in a Capital Group
Situation: Dispersed systems, inconsistent registers, and local processes requiring alignment with group standards.
Action: Inventory of resources, assignment of owners, organization of registers, and linking documentation with actual processes.
Result: Clear responsibilities, a consistent picture of processing, and a basis for group audits and reviews.
Preparing the Organization for NIS2/KSC
Situation: An organization operating within an international group needed to translate NIS2/KSC requirements into specific obligations, roles and priorities.
Action: Scope qualification, gap and risk analysis, responsibility mapping, and a practical implementation plan.
Result: Management received an organized overview of obligations, an action schedule and a basis for monitoring implementation.
Michał Rutkowski
Since 2004, I have combined technological experience with personal data protection and cybersecurity. I serve as a DPO, conduct audits and implementations, and support organizations in situations requiring risk assessment, organization of responsibilities and documented decision-making.
I work with medium and large organizations, including those belonging to international capital groups. I combine legal and group requirements with the actual processes, systems, resources and operational capabilities of organizations.
I combine perspectives crucial for organizations
Management Board and Executives
Responsibility, risk, and priorities.
IT and Security
Systems, safeguards, and remedial actions.
Law and Compliance
Compliance, documentation, and auditability of decisions.
Capital Group Companies
Local requirements, central standards, and inter-departmental cooperation.
Let’s talk about the situation in your organization
Briefly describe your needs. After reviewing the information, I will propose the appropriate first step and – if the scope is suitable – a date for a diagnostic conversation.
M.Rutkowski@LabLogic.pl
81-327 Gdynia, ul. Wolności 15
What happens after submitting the form
Application Analysis
I will review the situation description and assess what first step will be most appropriate.
Scope Definition
If the topic aligns with my area of support, I will propose a diagnostic conversation or a specific form of cooperation.
Secure Information Exchange
Confidential materials and incident details are only shared after agreeing on an appropriate communication channel.
Briefly describe your organization’s situation
The administrator of the data provided in the form is Michał Rutkowski, operating LabLogic Consulting. I use the data to handle inquiries and prepare a response or offer. Details can be found in the Privacy Policy. Do not send passwords, special categories of data, or full incident documentation.